Junglewise Threat Intelligence

CVE-2026-20481: MediaTek geniezone out-of-bounds write

CVE-2026-20481 · Severity: medium · CVSS 6 · Published 2026-08-03

Technologies: MediaTek Mt8797 Firmware, MediaTek Mt6989 Firmware, MediaTek MT8755, MediaTek Mt8791t, MediaTek Mt8910 Firmware, MediaTek Mt8775 Firmware, MediaTek Mt8798, MediaTek Mt8771, MediaTek Mt8791t Firmware, MediaTek MT8792, MediaTek MT8775, MediaTek Mt8796 Firmware, MediaTek Mt8797, MediaTek Mt8793 Firmware, MediaTek Mt8799, MediaTek Mt8910, MediaTek Mt8793, MediaTek Mt8771 Firmware, MediaTek Mt8792 Firmware, MediaTek Mt8781, MediaTek MT8796, MediaTek Mt8755 Firmware, MediaTek Mt8781 Firmware, MediaTek Mt6989, MediaTek Mt8799 Firmware, MediaTek Mt8768 Firmware, MediaTek Mt8768, MediaTek GenieZone. Vendors: MediaTek.

Executive brief

MediaTek's geniezone security component is vulnerable to an out-of-bounds memory write due to missing input validation. An attacker who already has system-level privileges could exploit this to escalate their access further or corrupt system memory, potentially leading to device compromise or malfunction.

Technical details

This vulnerability is a missing bounds check leading to an out-of-bounds write (CWE-787) in MediaTek's geniezone component. The flaw allows an attacker with System privilege to write data beyond allocated buffer boundaries. Since the advisory states that System privilege is required and user interaction is not needed, exploitation requires the attacker to already have elevated system access on the device. Successful exploitation could enable privilege escalation, memory corruption, or arbitrary code execution with system-level permissions. MediaTek issued patch ALPS10965373 to address this issue.

Affected products

  • MediaTek geniezone

Timeline

  • 2026-08-03: disclosed
  • 2026-08-03: patched: Patch ID: ALPS10965373

References

Related threats