Junglewise Threat Intelligence

CVE-2026-20517: MediaTek geniezone use-after-free privilege escalation

CVE-2026-20517 · Severity: medium · CVSS 6.7 · Published 2026-09-07

Technologies: MediaTek GenieZone. Vendors: MediaTek.

Executive brief

MediaTek's geniezone is a security-related component used in mobile chipsets. A use-after-free vulnerability in this component allows an attacker who has already gained system-level privileges to escalate their access further, with no user interaction required. This could enable a compromised device to be taken over completely.

Technical details

The vulnerability is a use-after-free memory safety flaw in MediaTek's geniezone component. The attack requires the attacker to already possess system privilege on the affected chipset. No user interaction is needed for exploitation. A successful exploit allows local privilege escalation. The vulnerability is tracked as CVE-2026-20517 with a CVSS score of 6.7 (medium severity). MediaTek has issued a patch with ID ALPS10900510 for affected chipsets.

Affected products

  • MediaTek geniezone <UNKNOWN>

Timeline

  • 2026-09-07: disclosed

References

Related threats