What is CVE-2026-20470?
A missing permission check vulnerability in the Telephony component of Android OS could lead to local information disclosure with no additional execution privileges needed. User interaction is not required for exploitation, and affected devices should be patched using the update identified by Patch ID ALPS11086431.
Azərbaycanca: Android əməliyyat sisteminin Telephony komponentində `missing permission check` zəifliyi aşkar edilib. Bu qüsur, heç bir əlavə icra imtiyazı tələb etmədən lokal məlumat sızmasına səbəb ola bilər. İstifadəçidən heç bir qarşılıqlı əlaqə tələb olunmur, təsirlənən cihazlarda ALPS11086431 yamaq identifikatoru ilə yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which Android component is affected by CVE-2026-20470?
This vulnerability affects the Telephony component of the Android operating system.
Which patch ID is assigned for CVE-2026-20470?
Patch ID ALPS11086431 has been assigned for this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.