Privilege Escalation Vulnerability in Aidl by MediaTek
CVE-2026-20535

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20535?

A vulnerability exists in the Aidl component of MediaTek products due to a missing permission check, which may allow a malicious actor with System privileges to escalate their privileges locally. The exploitation does not require user interaction, making it a significant risk. MediaTek has released Patch ID ALPS11185216 to address this issue.

Affected Version(s)

MediaTek chipset MT6878

MediaTek chipset MT6881

MediaTek chipset MT6899

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.