Junglewise Threat Intelligence

CVE-2026-20485: MediaTek HFRP out-of-bounds write privilege escalation

CVE-2026-20485 · Severity: medium · CVSS 6 · Published 2026-08-03

Technologies: MediaTek Mt6993 Firmware, MediaTek MT6993. Vendors: MediaTek.

Executive brief

MediaTek's HFRP (a component used in mobile chipsets) contains a missing bounds check that allows an attacker with System-level privileges to write data outside allocated memory. This vulnerability enables privilege escalation and could potentially allow an attacker to gain complete control of the device or cause it to malfunction.

Technical details

The vulnerability is an out-of-bounds write (CWE-787) in MediaTek's HFRP component, caused by a missing bounds check. An attacker who has already obtained System privilege can exploit this vulnerability without requiring user interaction to achieve local privilege escalation. The affected component likely resides in the firmware or bootloader code executed with elevated privileges. MediaTek has released patches (Patch ID: ALPS11049569) and this issue has not been observed in active exploitation as of the advisory publication date.

Affected products

  • MediaTek HFRP

Timeline

  • 2026-08-03: disclosed
  • 2026-08-03: patched: Patch ID ALPS11049569 released

References

Related threats