Executive brief
MiracastService is a core component in MediaTek chipsets that handles wireless display connectivity. This vulnerability allows a local attacker with basic user privileges to escalate their access without user interaction, potentially compromising device security and enabling denial of service attacks.
Technical details
CVE-2026-20516 is a confused deputy privilege escalation vulnerability in MediaTek's MiracastService component. The vulnerability allows a local attacker with user-level execution privileges to escalate their access through a confused deputy attack, without requiring user interaction. The root cause is improper authorization checking that allows an unprivileged process to perform operations reserved for higher-privilege contexts. An attacker can exploit this to execute arbitrary code with elevated privileges or trigger denial of service conditions. Patches are available via ALPS11060069 / DTV04881615; device OEMs were notified at least two months before public disclosure.
Affected products
- MediaTek MiracastService Affected chipsets include MT2716, MT2718, MT6580, MT6739, MT6761, MT6835, MT6858, MT6878, MT6881, MT6897, MT6899, MT6982VB, MT6986, MT6988, MT6991, MT6993, MT8668, MT8676, MT8678, MT8755, MT8775, MT8792, MT8793, MT8863, MT8873, MT8883
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Patch ID ALPS11060069 / DTV04881615 available