Executive brief
MediaTek's geniezone is a security-related component used in mobile chipsets. A use-after-free vulnerability in this component allows an attacker who has already gained system-level privileges to escalate their access further, with no user interaction required. This could enable a compromised device to be taken over completely.
Technical details
The vulnerability is a use-after-free memory safety flaw in MediaTek's geniezone component. The attack requires the attacker to already possess system privilege on the affected chipset. No user interaction is needed for exploitation. A successful exploit allows local privilege escalation. The vulnerability is tracked as CVE-2026-20517 with a CVSS score of 6.7 (medium severity). MediaTek has issued a patch with ID ALPS10900510 for affected chipsets.
Affected products
- MediaTek geniezone <UNKNOWN>
Timeline
- 2026-09-07: disclosed