Junglewise Threat Intelligence

CVE-2026-20495: MediaTek Bluetooth driver permission bypass

CVE-2026-20495 · Severity: high · CVSS 7.8 · Published 2026-08-03

Vendors: MediaTek.

Executive brief

MediaTek's Bluetooth driver, used in mobile and IoT devices, contains a missing permission check that allows a local user to escalate their privileges without requiring any user interaction. An attacker with basic user-level access could exploit this flaw to gain elevated system permissions, potentially compromising device security and enabling further attacks.

Technical details

The vulnerability is a missing permission check in the MediaTek Bluetooth driver, classified as an authorization bypass. An attacker with local user-level execution privileges can exploit this flaw without requiring user interaction or network access. By bypassing the permission check, an attacker achieves privilege escalation from user to a higher privilege level. The patch ID WCNCR00488300 has been provided, and MediaTek has notified device OEMs of the fix for at least two months before public disclosure.

Affected products

  • MediaTek Bluetooth driver

Timeline

  • 2026-08-03: disclosed
  • 2026-08-03: advisory: MediaTek Product Security Bulletin August 2026

References

Related threats