Junglewise Threat Intelligence

CVE-2026-20509: MediaTek Power HAL out-of-bounds write

CVE-2026-20509 · Severity: medium · CVSS 6.7 · Published 2026-09-07

Vendors: MediaTek.

Executive brief

MediaTek Power HAL is a firmware component that manages power consumption on Android devices. A missing bounds check allows an attacker with System-level privileges to write data outside memory boundaries, potentially escalating privileges further or crashing the device. This could be chained with other vulnerabilities to compromise device security.

Technical details

The vulnerability is an out-of-bounds write caused by missing bounds validation in MediaTek Power HAL. An attacker with System privilege can trigger the condition without user interaction, writing arbitrary data beyond allocated buffer boundaries. This heap or stack corruption can lead to privilege escalation, memory corruption, or denial of service. A patch (ALPS11165543) is available from MediaTek; affected devices should apply the September 2026 security update.

Affected products

  • MediaTek Power HAL <UNKNOWN>

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Patch ID ALPS11165543

References

Related threats