Video HAL Vulnerability in MediaTek Products Leading to Privilege Escalation
CVE-2026-20521

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20521?

A vulnerability exists in MediaTek's Video HAL that may allow a local user to escalate their privileges due to a missing bounds check. This flaw can be exploited without requiring additional execution privileges or user interaction, making it a significant security risk. Affected users should apply the patch indicated by Patch ID ALPS11375674 to mitigate this vulnerability.

Affected Version(s)

MediaTek chipset MT2718

MediaTek chipset MT6768

MediaTek chipset MT6769

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.