Junglewise Threat Intelligence

CVE-2026-20518: MediaTek Geniezone information disclosure via missing bounds check

CVE-2026-20518 · Severity: medium · CVSS 4.4 · Published 2026-09-07

Technologies: MediaTek GenieZone. Vendors: MediaTek.

Executive brief

MediaTek Geniezone is a trusted execution environment (TEE) security processor embedded in MediaTek chipsets used in Android smartphones and IoT devices. An attacker who already has System-level privileges can exploit a missing bounds check to read sensitive data from protected memory, requiring user interaction to succeed. This vulnerability could expose confidential information such as cryptographic keys, authentication tokens, or user data that should remain isolated.

Technical details

The vulnerability is a missing bounds check in the Geniezone TEE that permits an out-of-bounds information disclosure. An attacker must already possess System privilege (a high-level precondition) and requires user interaction to trigger the exploit. The vulnerability allows unauthorized memory access and data exfiltration from protected memory regions. The missing bounds validation occurs at the input or buffer handling level, enabling reads beyond allocated memory. MediaTek has issued patches identified as ALPS10867524 and ALPS10876355 to remediate the issue.

Affected products

  • MediaTek Geniezone

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Patches ALPS10867524 / ALPS10876355 released

References

Related threats