What is CVE-2026-20488?
This vulnerability allows a malicious actor with System privileges to achieve local information disclosure through a missing bounds check in the display component. User interaction is not required for exploitation. Apply patch ID ALPS11004276 to affected devices.
Azərbaycanca: Bu zəiflik, artıq System imtiyazına malik olan təcavüzkarın display komponentindəki `bounds check` çatışmazlığı səbəbindən lokal məlumat sızıntısına yol aça bilər. İstifadəçi qarşılıqlı əlaqəsi tələb olunmur. Təsirlənən cihazlar üçün ALPS11004276 nömrəli yamaq tətbiq edilməlidir.
FAQ1
What privileges must an attacker have to successfully exploit CVE-2026-20488?
The attacker must already have System privileges to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.