Memory Corruption Vulnerability in MediaTek AIDL Component
CVE-2026-20537

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20537?

A memory corruption vulnerability in MediaTek's AIDL component has been identified that could allow an attacker with system privileges to escalate their privileges on the affected device. The exploit does not require any user interaction, making it a significant concern for device security. This vulnerability stems from improper handling of memory that leads to use after free scenarios. It is crucial for users to apply the available patch (ALPS11185225) to safeguard their systems and mitigate potential attacks.

Affected Version(s)

MediaTek chipset MT6878

MediaTek chipset MT6881

MediaTek chipset MT6899

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.