Local Privilege Escalation Vulnerability in Apusys by MediaTek
CVE-2026-20467

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
3 August 2026

What is CVE-2026-20467?

A local privilege escalation vulnerability exists in Apusys due to a missing bounds check. This issue allows an attacker who has obtained System privileges to escalate their access without needing any user interaction. This makes it particularly dangerous as it can be executed stealthily. MediaTek has provided a patch (ID: AUTO00837766) for this issue under Issue ID: MSV-6767, urging users to apply it to secure their systems.

Affected Version(s)

MediaTek chipset MT8195

MediaTek chipset MT8196

MediaTek chipset MT8366

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.