What is CVE-2026-20494?
CVE-2026-20494 is an out of bounds read vulnerability in the Wi-Fi component caused by a missing bounds check. It could lead to local information disclosure if a malicious actor has already obtained System privilege, with no user interaction required. Apply the patches with IDs ALPS10960006, BORA00155314, BORA00155001 to mitigate the issue.
Azərbaycanca: CVE-2026-20494 Wi-Fi komponentində sərhəd yoxlamasının olmaması səbəbindən yaranan out of bounds read zəifliyidir. Bu zəiflik, hücumçu artıq System imtiyazı əldə etdikdə lokal məlumat ifşasına səbəb ola bilər. Təsirə məruz qalmamaq üçün ALPS10960006, BORA00155314, BORA00155001 ID-li yamalar tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which component is affected by CVE-2026-20494 and what is its root cause?
The vulnerability affects the Wi-Fi component. Its root cause is a missing bounds check, which leads to an out of bounds read condition.
Which patches should be applied to mitigate CVE-2026-20494?
Patches with the IDs ALPS10960006, BORA00155314, and BORA00155001 should be applied to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.