Junglewise Threat Intelligence

CVE-2026-20492: MediaTek Audio HAL race condition denial of service

CVE-2026-20492 · Severity: medium · CVSS 5.5 · Published 2026-08-03

Technologies: MediaTek Mt6990 Firmware, MediaTek Mt6880, MediaTek MT6988, MediaTek Mt2737 Firmware, MediaTek Mt2735 Firmware, MediaTek MT2735, MediaTek Mt6988 Firmware, MediaTek Mt6890 Firmware, MediaTek MT6990, MediaTek MT2737, MediaTek Mt6880 Firmware, MediaTek Mt6890. Vendors: MediaTek.

Executive brief

MediaTek's Audio HAL (Hardware Abstraction Layer) is a core component that manages audio functionality in devices using MediaTek chipsets. A race condition flaw allows a local attacker with user privileges to make the system unresponsive, disrupting audio and potentially broader device functionality without requiring user interaction.

Technical details

The vulnerability is a race condition in the Audio HAL component affecting MediaTek chipsets including MT6880, MT6890, MT6990, MT6988, MT2735, and MT2737. The race condition can be triggered by a local attacker with user execution privileges to cause a denial of service condition that renders the system unresponsive. No user interaction is required for exploitation. Patches are available under Patch ID ALPS10960026 (for MT6880, MT6890, MT6990, MT6988) and AUTO00851250 (for MT2735, MT2737).

Affected products

  • MediaTek MT6880 affected
  • MediaTek MT6890 affected
  • MediaTek MT6990 affected
  • MediaTek MT6988 affected
  • MediaTek MT2735 affected
  • MediaTek MT2737 affected

Timeline

  • 2026-08-03: disclosed
  • 2026-08-03: patched: Patches ALPS10960026 and AUTO00851250 available

References

Related threats