Junglewise Threat Intelligence

CVE-2026-20508: MediaTek Power HAL privilege escalation via type confusion

CVE-2026-20508 · Severity: medium · CVSS 6.7 · Published 2026-09-07

Vendors: MediaTek.

Executive brief

Power HAL is a critical system component in MediaTek chipsets that manages power distribution and performance on Android devices. A type confusion vulnerability allows an attacker who already has system-level privileges to escalate their access further, potentially gaining complete control over the device without needing user interaction.

Technical details

The vulnerability is a type confusion flaw in MediaTek's Power HAL component that leads to local privilege escalation. The attack requires the attacker to already possess system privilege; no user interaction is required for exploitation. The type confusion allows an attacker to bypass type safety checks and execute arbitrary code with elevated privileges. A patch has been issued (Patch ID: ALPS11165543) and affected devices should apply available security updates from their OEMs.

Affected products

  • MediaTek Power HAL

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Patch ID: ALPS11165543

References

Related threats