Junglewise Threat Intelligence

CVE-2026-20486: MediaTek imgsensor application crash due to incorrect error handling

CVE-2026-20486 · Severity: medium · CVSS 6.7 · Published 2026-08-03

Technologies: MediaTek Mt6878 Firmware, MediaTek Mt6895 Firmware, MediaTek Mt6993 Firmware, MediaTek Mt8910 Firmware, MediaTek Mt6878, MediaTek Mt6991, MediaTek Mt8395, MediaTek Mt2718 Firmware, MediaTek MT6993, MediaTek Mt2718, MediaTek Mt8799, MediaTek Mt6991 Firmware, MediaTek Mt8910, MediaTek Mt8678 Firmware, MediaTek Mt8395 Firmware, MediaTek Mt6895, MediaTek Mt8799 Firmware, MediaTek MT8678. Vendors: MediaTek.

Executive brief

MediaTek's imgsensor component handles camera image processing on mobile chipsets. A flaw in its error handling can cause the application to crash unexpectedly. While the crash itself may seem benign, an attacker who already has System-level privileges could exploit this to escalate or maintain their access to the device.

Technical details

The vulnerability is a local privilege escalation flaw caused by incorrect error handling in the imgsensor subcomponent. The issue manifests as an application crash that can be triggered by a malicious actor who has already obtained System privilege on the device. No user interaction is required for exploitation. The vulnerability affects MediaTek chipsets and is addressed by patch ID ALPS11012302 (Issue ID MSV-7833). The attack vector is local, requiring an attacker to already have elevated system privileges.

Affected products

  • MediaTek imgsensor <UNKNOWN>

Timeline

  • 2026-08-03: disclosed
  • 2026-08-03: patched: Patch ID ALPS11012302; Issue ID MSV-7833

References

Related threats