Junglewise Threat Intelligence

CVE-2026-20473: MediaTek display memory corruption use-after-free

CVE-2026-20473 · Severity: medium · CVSS 6 · Published 2026-08-03

Technologies: MediaTek Mt8367, MediaTek Mt8126 Firmware, MediaTek Mt8367 Firmware, MediaTek Mt8786 Firmware, MediaTek MT8676, MediaTek Mt8188 Firmware, MediaTek Mt6993 Firmware, MediaTek Mt8791t, MediaTek Mt8910 Firmware, MediaTek Mt6991, MediaTek MT6993, MediaTek Mt8676 Firmware, MediaTek Mt8791t Firmware, MediaTek Mt8126, MediaTek Mt8766, MediaTek Mt8766 Firmware, MediaTek Mt8668, MediaTek Mt8799, MediaTek Mt8188, MediaTek Mt8189, MediaTek Mt6991 Firmware, MediaTek Mt8910, MediaTek Mt8781, MediaTek Mt8189 Firmware, MediaTek Mt8678 Firmware, MediaTek Mt8668 Firmware, MediaTek Mt8781 Firmware, MediaTek Mt8171, MediaTek Mt8799 Firmware, MediaTek MT8678, MediaTek Mt8768 Firmware, MediaTek Mt8786, MediaTek Mt8171 Firmware, MediaTek Mt8768. Vendors: MediaTek.

Executive brief

MediaTek chipsets include display processing components that render graphics on smartphones, tablets, and other devices. A memory corruption vulnerability in the display driver could allow an attacker who has already gained system-level access to escalate privileges or crash the device, affecting the reliability and security of the affected systems.

Technical details

This is a use-after-free memory corruption vulnerability in the display subcomponent of MediaTek chipsets. The root cause involves improper memory management leading to access of freed memory regions. Exploitation requires that an attacker has already obtained System privilege, meaning local access to the device. No user interaction is required once System privilege is obtained. Successful exploitation can lead to local privilege escalation. A patch is available as indicated by Patch ID ALPS11019722.

Affected products

  • MediaTek Dimensity

Timeline

  • 2026-08-03: disclosed

References

Related threats