Out of Bounds Write Vulnerability in Neuropilot by MediaTek
CVE-2026-20523

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20523?

In Neuropilot, a vulnerability exists that can lead to an out-of-bounds write due to a missing bounds check. This issue allows for local escalation of privileges without the need for additional execution permissions. Exploitation does not require user interaction, making it a significant security concern. Prompt application of the available patch (ALPS11249062) is recommended to mitigate potential risks associated with this vulnerability.

Affected Version(s)

MediaTek chipset MT6881

MediaTek chipset MT6993

MediaTek chipset MT8188

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.