MediaTek chipset: imgsensor crash leads to privilege escalation
CVE-2026-20486 Published on August 3, 2026
In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833.
Vulnerability Analysis
CVE-2026-20486 is exploitable with local system access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Improper Check for Unusual or Exceptional Conditions
The software does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the software.
Affected Versions
MediaTek, Inc. MediaTek chipset:- Version MT2718 is affected.
- Version MT6878 is affected.
- Version MT6895 is affected.
- Version MT6991 is affected.
- Version MT6993 is affected.
- Version MT8370 is affected.
- Version MT8390 is affected.
- Version MT8395 is affected.
- Version MT8678 is affected.
- Version MT8799 is affected.
- Version MT8910 is affected.