Junglewise Threat Intelligence

CVE-2026-20468: MediaTek apusys confused deputy privilege escalation

CVE-2026-20468 · Severity: medium · CVSS 6 · Published 2026-08-03

Vendors: MediaTek.

Executive brief

MediaTek apusys is a system component found in MediaTek chipsets that manages resource access and privilege levels. A vulnerability in apusys allows a malicious actor with System privilege to escalate their privileges further through a confused deputy attack. This could enable complete control of affected devices.

Technical details

CVE-2026-20468 is a privilege escalation vulnerability in the MediaTek apusys component caused by a confused deputy issue. The vulnerability requires the attacker to already have System-level privilege on the device, with no user interaction needed for exploitation. The confused deputy weakness allows the attacker to trick a higher-privileged process into performing unauthorized actions on their behalf, leading to local privilege escalation. A patch is available (Patch ID: AUTO00833804).

Affected products

  • MediaTek apusys <UNKNOWN>

Timeline

  • 2026-08-03: disclosed

References

Related threats