Memory Corruption in Apusys Affects MediaTek Products
CVE-2026-20542

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20542?

A memory corruption vulnerability exists in Apusys that stems from a use-after-free error. This issue can enable local escalation of privilege for an attacker who has already gained system-level access. Critically, the attack does not require user interaction, making it a significant concern for affected systems. A patch is available, identified as ALPS11076799, addressing this issue under Issue ID MSV-8143. For detailed information, please refer to the official MediaTek product security bulletin.

Affected Version(s)

MediaTek chipset MT2718

MediaTek chipset MT6878

MediaTek chipset MT6897

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.