CVE-2019-20556: Google Android

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered on Samsung mobile devices with P(9.0) (SM6150, SM8150, SM8150_FUSION, exynos7885, exynos9610, and exynos9820 chipsets) software. RKP memory corruption allows attackers to control the effective address in EL2. The Samsung ID is SVE-2019-15221 (October 2019).

Affected products

  • Google Android: version 9.0 only

Published 2020-03-24. Last modified 2026-06-17.