Executive brief
MediaTek APUSys is a system component used in MediaTek chipsets that manages AI and processing tasks in smartphones and other devices. A missing bounds check vulnerability allows an attacker with existing System-level privileges to escalate their access further without user interaction, potentially gaining complete control over the device.
Technical details
This vulnerability is a missing bounds check in the APUSys component that can lead to privilege escalation. An attacker must already possess System-level privileges to exploit this flaw. The attack vector is local and does not require user interaction. Successful exploitation allows the attacker to achieve further privilege escalation on the affected device. Patches have been provided to device OEMs (Patch ID: AUTO00837766) and device manufacturers have had at least two months to deploy fixes before this disclosure.
Affected products
- MediaTek APUSys <UNKNOWN>
Timeline
- 2026-08-03: disclosed
- 2026-06-03: patched: Patches provided to OEMs approximately 2 months before public disclosure