CVE Vulnerabilities

CVE-2026-20970

Published: Jan 09, 2026 | Modified: Jan 15, 2026
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs.

Affected Software

NameVendorStart VersionEnd Version
AndroidSamsung15.0-smr-apr-2025-r1 (including)15.0-smr-apr-2025-r1 (including)
AndroidSamsung15.0-smr-aug-2025-r1 (including)15.0-smr-aug-2025-r1 (including)
AndroidSamsung15.0-smr-dec-2025-r1 (including)15.0-smr-dec-2025-r1 (including)
AndroidSamsung15.0-smr-feb-2025-r1 (including)15.0-smr-feb-2025-r1 (including)
AndroidSamsung15.0-smr-jul-2025-r1 (including)15.0-smr-jul-2025-r1 (including)
AndroidSamsung15.0-smr-jun-2025-r1 (including)15.0-smr-jun-2025-r1 (including)
AndroidSamsung15.0-smr-mar-2025-r1 (including)15.0-smr-mar-2025-r1 (including)
AndroidSamsung15.0-smr-may-2025-r1 (including)15.0-smr-may-2025-r1 (including)
AndroidSamsung15.0-smr-nov-2025-r1 (including)15.0-smr-nov-2025-r1 (including)
AndroidSamsung15.0-smr-oct-2025-r1 (including)15.0-smr-oct-2025-r1 (including)
AndroidSamsung15.0-smr-sep-2025-r1 (including)15.0-smr-sep-2025-r1 (including)
AndroidSamsung16.0-smr-aug-2025-r1 (including)16.0-smr-aug-2025-r1 (including)
AndroidSamsung16.0-smr-dec-2025-r1 (including)16.0-smr-dec-2025-r1 (including)
AndroidSamsung16.0-smr-nov-2025-r1 (including)16.0-smr-nov-2025-r1 (including)
AndroidSamsung16.0-smr-oct-2025-r1 (including)16.0-smr-oct-2025-r1 (including)
AndroidSamsung16.0-smr-sep-2025-r1 (including)16.0-smr-sep-2025-r1 (including)

References