Junglewise Threat Intelligence

CVE-2026-20474: MediaTek display driver privilege escalation via race condition

CVE-2026-20474 · Severity: medium · CVSS 6 · Published 2026-08-03

Technologies: MediaTek Mt8786 Firmware, MediaTek MT8676, MediaTek Mt6993 Firmware, MediaTek Mt8367, MediaTek Mt8791t, MediaTek Mt8910 Firmware, MediaTek Mt6991, MediaTek Mt8188 Firmware, MediaTek MT6993, MediaTek Mt8367 Firmware, MediaTek Mt8676 Firmware, MediaTek Mt8791t Firmware, MediaTek Mt8799 Firmware, MediaTek Mt8126 Firmware, MediaTek Mt8766, MediaTek Mt8189 Firmware, MediaTek Mt8766 Firmware, MediaTek Mt8668, MediaTek Mt8126, MediaTek Mt8171, MediaTek Mt6991 Firmware, MediaTek Mt8910, MediaTek Mt8188, MediaTek Mt8171 Firmware, MediaTek Mt8781, MediaTek Mt8678 Firmware, MediaTek Mt8668 Firmware, MediaTek Mt8781 Firmware, MediaTek MT8678, MediaTek Mt8189, MediaTek Mt8768 Firmware, MediaTek Mt8786, MediaTek Mt8799, MediaTek Mt8768. Vendors: MediaTek.

Executive brief

A race condition vulnerability exists in MediaTek chipset display drivers that allows privilege escalation. An attacker who already holds System-level privileges can exploit this to elevate privileges further, with no user interaction required. This could be leveraged as part of a multi-stage attack to gain complete control of affected devices.

Technical details

The vulnerability is a race condition in the display subsystem that leads to local privilege escalation. The vulnerability requires that an attacker has already obtained System privilege level access; no additional user interaction is needed for exploitation. The exact vulnerable component and root cause are not detailed in the available information, but the race condition allows privilege boundary bypass. A patch has been issued (Patch ID: ALPS11019183) by MediaTek and is available through their August 2026 security bulletin.

Affected products

  • MediaTek display driver <UNKNOWN>

Timeline

  • 2026-08-03: disclosed
  • 2026-08-03: patched: Patch ID: ALPS11019183

References

Related threats