Application Crash Vulnerability in imgsensor by MediaTek
CVE-2026-20486

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
3 August 2026

What is CVE-2026-20486?

The imgsensor component by MediaTek is susceptible to an application crash caused by improper error handling. This vulnerability could enable local privilege escalation for attackers who have already gained system privileges. Notably, user interaction is not required for exploitation, making it a serious concern for affected systems. A patch has been issued (Patch ID: ALPS11012302) to address this issue, emphasizing the importance of updating to secure versions.

Affected Version(s)

MediaTek chipset MT2718

MediaTek chipset MT6878

MediaTek chipset MT6895

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.