Executive brief
MediaTek apusys is a system component found in MediaTek chipsets that manages resource access and privilege levels. A vulnerability in apusys allows a malicious actor with System privilege to escalate their privileges further through a confused deputy attack. This could enable complete control of affected devices.
Technical details
CVE-2026-20468 is a privilege escalation vulnerability in the MediaTek apusys component caused by a confused deputy issue. The vulnerability requires the attacker to already have System-level privilege on the device, with no user interaction needed for exploitation. The confused deputy weakness allows the attacker to trick a higher-privileged process into performing unauthorized actions on their behalf, leading to local privilege escalation. A patch is available (Patch ID: AUTO00833804).
Affected products
- MediaTek apusys <UNKNOWN>
Timeline
- 2026-08-03: disclosed