Local Privilege Escalation Vulnerability in MediaTek Products
CVE-2026-20427

6.7MEDIUM

What is CVE-2026-20427?

A vulnerability exists within MediaTek products where improper bounds checking could allow an attacker with system privileges to escalate their access locally. This means that if a malicious actor gains system-level access, they could exploit this flaw to elevate their privileges further, potentially compromising the affected system's integrity. The exploitation does not require user interaction, making it particularly concerning for users of the affected MediaTek software versions. Affected users should apply the security patch ALPS10320471 promptly to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6897, MT6899, MT6983, MT6985, MT6989, MT6991, MT6993, MT8196, MT8678, MT8793 Android 14.0, 15.0, 16.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.