Privilege Escalation Vulnerability in GenieZone by MediaTek
CVE-2026-20498

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
3 August 2026

What is CVE-2026-20498?

The GenieZone product by MediaTek exhibits a privilege escalation vulnerability caused by a missing permission check. This flaw allows attackers who have already gained system privileges to escalate their access without requiring user interaction. The absence of adequate checks may enable a malicious actor to exploit system functionalities, potentially compromising sensitive information or resources. MediaTek has identified the issue under Patch ID: ALPS10900493 and Issue ID: MSV-6765. Immediate remediation is recommended to mitigate risks associated with this vulnerability.

Affected Version(s)

MediaTek chipset MT6991

MediaTek chipset MT8768

MediaTek chipset MT8791T

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.