MediaTek Chipset Priv Escalation via Bounds Check
CVE-2026-20467 Published on August 3, 2026
In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767.
Vulnerability Analysis
CVE-2026-20467 can be exploited with local system access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Exposed Dangerous Method or Function
The software provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
Affected Versions
MediaTek, Inc. MediaTek chipset:- Version MT8195 is affected.
- Version MT8196 is affected.
- Version MT8366 is affected.