Out of Bounds Write Vulnerability in imgsys by MediaTek
CVE-2026-20409
7.8HIGH
What is CVE-2026-20409?
In imgsys, a potential out of bounds write issue arises from a missing bounds check, which may allow a malicious user with existing System privileges to escalate their privileges on the device. Exploitation of this vulnerability does not require user interaction, making it a significant security concern. Affected users are advised to apply the provided patch (Patch ID: ALPS10363246) promptly to mitigate risks.
Affected Version(s)
MediaTek chipset MT6897
MediaTek chipset MT6989
