Privilege Escalation Vulnerability in GenieZone by MediaTek
CVE-2026-20498
Currently unrated
What is CVE-2026-20498?
The GenieZone product by MediaTek exhibits a privilege escalation vulnerability caused by a missing permission check. This flaw allows attackers who have already gained system privileges to escalate their access without requiring user interaction. The absence of adequate checks may enable a malicious actor to exploit system functionalities, potentially compromising sensitive information or resources. MediaTek has identified the issue under Patch ID: ALPS10900493 and Issue ID: MSV-6765. Immediate remediation is recommended to mitigate risks associated with this vulnerability.
Affected Version(s)
MediaTek chipset MT6991
MediaTek chipset MT8768
MediaTek chipset MT8791T
