Junglewise Threat Intelligence

CVE-2026-20475: MediaTek display out-of-bounds write privilege escalation

CVE-2026-20475 · Severity: medium · CVSS 6 · Published 2026-08-03

Technologies: MediaTek Mt8367, MediaTek Mt8126 Firmware, MediaTek Mt8367 Firmware, MediaTek Mt8786 Firmware, MediaTek MT8676, MediaTek Mt8188 Firmware, MediaTek Mt6993 Firmware, MediaTek Mt8791t, MediaTek Mt8910 Firmware, MediaTek Mt6991, MediaTek MT6993, MediaTek Mt8676 Firmware, MediaTek Mt8791t Firmware, MediaTek Mt8126, MediaTek Mt8766, MediaTek Mt8766 Firmware, MediaTek Mt8668, MediaTek Mt8799, MediaTek Mt8188, MediaTek Mt8189, MediaTek Mt6991 Firmware, MediaTek Mt8910, MediaTek Mt8781, MediaTek Mt8189 Firmware, MediaTek Mt8678 Firmware, MediaTek Mt8668 Firmware, MediaTek Mt8781 Firmware, MediaTek Mt8171, MediaTek Mt8799 Firmware, MediaTek MT8678, MediaTek Mt8768 Firmware, MediaTek Mt8786, MediaTek Mt8171 Firmware, MediaTek Mt8768. Vendors: MediaTek.

Executive brief

MediaTek chipsets include a display component with a missing bounds check that allows an attacker with System privilege to trigger an out-of-bounds write. An attacker who has already compromised system-level access could exploit this flaw to escalate privileges further, potentially gaining complete control of the device. No user interaction is required once system-level access is obtained.

Technical details

This is an out-of-bounds write vulnerability (CWE-787) in the display subsystem of affected MediaTek chipsets, caused by a missing bounds check. The vulnerability requires the attacker to have already obtained System privilege level access; it is a local privilege escalation vector for an unprivileged-to-privileged boundary crossing. Exploitation does not require user interaction. The flaw affects display processing logic and can lead to memory corruption, enabling further privilege escalation. MediaTek has issued security patch ALPS11004276 (Issue ID MSV-7748) to address this issue.

Affected products

  • MediaTek MT6761 Chipset Unspecified

Timeline

  • 2026-08-03: disclosed
  • other: Patch ID ALPS11004276 issued; OEMs notified 2+ months prior to publication

References

Related threats