Out-of-Bounds Write Vulnerability in Power HAL by MediaTek
CVE-2026-20509

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
7 September 2026

What is CVE-2026-20509?

A critical out-of-bounds write vulnerability exists in the Power HAL component of MediaTek's software stack, caused by a lack of proper bounds checking. This issue can enable a local attacker, who has already gained System privileges, to escalate their access to higher privileges. Exploitation does not require any user interaction, making this vulnerability particularly concerning. Users are encouraged to apply the security patch identified as ALPS11165543 to mitigate this risk.

Affected Version(s)

MediaTek chipset MT2718

MediaTek chipset MT6739

MediaTek chipset MT6761

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.