CVE-2026-20511: Use After Free
Published Sep 7, 2026
·Updated
In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11123860; Issue ID: MSV-8890.
Affected Software
1 affected component
Google SurfaceFlinger
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS11123860
Event History
Sep 7, 2026
CVE Published
via MITRE·01:57 AM
Data Sourced
via MITRE·01:57 AM
DescriptionWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need before exploiting this issue?
The attacker must already have System privilege. The described impact is local escalation of privilege from that existing level of access.
2
Is user interaction required for exploitation?
No. Exploitation does not require user interaction.
3
What patch identifier should defenders track?
Track patch ID ALPS11123860. The associated issue ID is MSV-8890.