Description
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791.
Published: 2026-06-01
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing bounds check in the MediaTek geniezone component can cause an out‑of‑bounds write. If an attacker already possesses System privileges on the device, this flaw can be triggered without any additional user interaction, turning a local user into a privileged process. The consequence is the potential compromise of data integrity and confidentiality, or the ability to further exploit the system after gaining higher privileges. The weakness corresponds to CWE‑787, an out‑of‑bounds write bug.

Affected Systems

The vulnerability affects devices that run the MediaTek chipset with the geniezone subsystem. No specific firmware or hardware version is listed, implying that all exposed geniezone implementations on MediaTek chipsets are potentially impacted until a patch is applied.

Risk and Exploitability

Because exploitation requires only local System privileges and no user action, the attack vector is local. The CVSS severity is 6.7, indicating a moderate to high risk. There is no EPSS score available, and the vulnerability is not listed in the CISA KEV catalog, yet the potential impact justifies prompt remediation.

Generated by OpenCVE AI on June 1, 2026 at 12:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the MediaTek security update identified by patch ALPS10886526 (Issue ID MSV‑6791).
  • Reboot the device after installing the patch to ensure updated code is active.
  • Restrict or disable direct access to the geniezone subsystem until the patch is applied or an additional mitigation measure is implemented.

Generated by OpenCVE AI on June 1, 2026 at 12:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 01 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mt6739
Mediatek mt6739 Firmware
Mediatek mt6761
Mediatek mt6761 Firmware
Mediatek mt6765
Mediatek mt6765 Firmware
Mediatek mt6768
Mediatek mt6768 Firmware
Mediatek mt6781
Mediatek mt6781 Firmware
Mediatek mt6789
Mediatek mt6789 Firmware
Mediatek mt6835
Mediatek mt6835 Firmware
Mediatek mt6853
Mediatek mt6853 Firmware
Mediatek mt6855
Mediatek mt6855 Firmware
Mediatek mt6877
Mediatek mt6877 Firmware
Mediatek mt6878
Mediatek mt6878 Firmware
Mediatek mt6879
Mediatek mt6879 Firmware
Mediatek mt6883
Mediatek mt6883 Firmware
Mediatek mt6885
Mediatek mt6885 Firmware
Mediatek mt6886
Mediatek mt6886 Firmware
Mediatek mt6889
Mediatek mt6889 Firmware
Mediatek mt6893
Mediatek mt6893 Firmware
Mediatek mt6895
Mediatek mt6895 Firmware
Mediatek mt6897
Mediatek mt6897 Firmware
Mediatek mt6899
Mediatek mt6899 Firmware
Mediatek mt6983
Mediatek mt6983 Firmware
Mediatek mt6985
Mediatek mt6985 Firmware
Mediatek mt6989
Mediatek mt6989 Firmware
Mediatek mt6991
Mediatek mt6991 Firmware
Mediatek mt8673
Mediatek mt8673 Firmware
Mediatek mt8765
Mediatek mt8765 Firmware
Mediatek mt8766
Mediatek mt8766 Firmware
Mediatek mt8768
Mediatek mt8768 Firmware
Mediatek mt8781
Mediatek mt8781 Firmware
Mediatek mt8786
Mediatek mt8786 Firmware
Mediatek mt8788
Mediatek mt8788 Firmware
Mediatek mt8791t
Mediatek mt8791t Firmware
Mediatek mt8793
Mediatek mt8793 Firmware
Mediatek mt8797
Mediatek mt8797 Firmware
Mediatek mt8798
Mediatek mt8798 Firmware
Mediatek mt8910
Mediatek mt8910 Firmware
CPEs cpe:2.3:h:mediatek:mt6739:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6761:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6765:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6781:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6789:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6835:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6878:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6883:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6885:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6886:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6889:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6897:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6899:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6985:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6989:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6991:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8765:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8766:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8786:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8788:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8793:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8797:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8910:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6739_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6761_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6765_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6768_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6781_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6789_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6835_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6853_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6855_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6877_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6878_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6879_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6883_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6885_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6886_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6889_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6893_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6895_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6897_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6899_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6983_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6985_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6989_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6991_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8673_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8765_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8766_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8768_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8781_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8786_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8788_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8791t_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8793_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8797_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8798_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8910_firmware:-:*:*:*:*:*:*:*
Vendors & Products Mediatek
Mediatek mt6739
Mediatek mt6739 Firmware
Mediatek mt6761
Mediatek mt6761 Firmware
Mediatek mt6765
Mediatek mt6765 Firmware
Mediatek mt6768
Mediatek mt6768 Firmware
Mediatek mt6781
Mediatek mt6781 Firmware
Mediatek mt6789
Mediatek mt6789 Firmware
Mediatek mt6835
Mediatek mt6835 Firmware
Mediatek mt6853
Mediatek mt6853 Firmware
Mediatek mt6855
Mediatek mt6855 Firmware
Mediatek mt6877
Mediatek mt6877 Firmware
Mediatek mt6878
Mediatek mt6878 Firmware
Mediatek mt6879
Mediatek mt6879 Firmware
Mediatek mt6883
Mediatek mt6883 Firmware
Mediatek mt6885
Mediatek mt6885 Firmware
Mediatek mt6886
Mediatek mt6886 Firmware
Mediatek mt6889
Mediatek mt6889 Firmware
Mediatek mt6893
Mediatek mt6893 Firmware
Mediatek mt6895
Mediatek mt6895 Firmware
Mediatek mt6897
Mediatek mt6897 Firmware
Mediatek mt6899
Mediatek mt6899 Firmware
Mediatek mt6983
Mediatek mt6983 Firmware
Mediatek mt6985
Mediatek mt6985 Firmware
Mediatek mt6989
Mediatek mt6989 Firmware
Mediatek mt6991
Mediatek mt6991 Firmware
Mediatek mt8673
Mediatek mt8673 Firmware
Mediatek mt8765
Mediatek mt8765 Firmware
Mediatek mt8766
Mediatek mt8766 Firmware
Mediatek mt8768
Mediatek mt8768 Firmware
Mediatek mt8781
Mediatek mt8781 Firmware
Mediatek mt8786
Mediatek mt8786 Firmware
Mediatek mt8788
Mediatek mt8788 Firmware
Mediatek mt8791t
Mediatek mt8791t Firmware
Mediatek mt8793
Mediatek mt8793 Firmware
Mediatek mt8797
Mediatek mt8797 Firmware
Mediatek mt8798
Mediatek mt8798 Firmware
Mediatek mt8910
Mediatek mt8910 Firmware

Mon, 01 Jun 2026 13:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in MediaTek GenieZone Enables Local Privilege Escalation

Mon, 01 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 01 Jun 2026 06:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in MediaTek GenieZone Enables Local Privilege Escalation

Mon, 01 Jun 2026 04:00:00 +0000

Type Values Removed Values Added
Description In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791.
Weaknesses CWE-787
References

Subscriptions

Mediatek Mt6739 Mt6739 Firmware Mt6761 Mt6761 Firmware Mt6765 Mt6765 Firmware Mt6768 Mt6768 Firmware Mt6781 Mt6781 Firmware Mt6789 Mt6789 Firmware Mt6835 Mt6835 Firmware Mt6853 Mt6853 Firmware Mt6855 Mt6855 Firmware Mt6877 Mt6877 Firmware Mt6878 Mt6878 Firmware Mt6879 Mt6879 Firmware Mt6883 Mt6883 Firmware Mt6885 Mt6885 Firmware Mt6886 Mt6886 Firmware Mt6889 Mt6889 Firmware Mt6893 Mt6893 Firmware Mt6895 Mt6895 Firmware Mt6897 Mt6897 Firmware Mt6899 Mt6899 Firmware Mt6983 Mt6983 Firmware Mt6985 Mt6985 Firmware Mt6989 Mt6989 Firmware Mt6991 Mt6991 Firmware Mt8673 Mt8673 Firmware Mt8765 Mt8765 Firmware Mt8766 Mt8766 Firmware Mt8768 Mt8768 Firmware Mt8781 Mt8781 Firmware Mt8786 Mt8786 Firmware Mt8788 Mt8788 Firmware Mt8791t Mt8791t Firmware Mt8793 Mt8793 Firmware Mt8797 Mt8797 Firmware Mt8798 Mt8798 Firmware Mt8910 Mt8910 Firmware
Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-06-02T03:55:39.373Z

Reserved: 2025-11-03T01:30:59.013Z

Link: CVE-2026-20453

cve-icon Vulnrichment

Updated: 2026-06-01T11:02:46.851Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-01T04:16:21.900

Modified: 2026-06-01T18:11:48.047

Link: CVE-2026-20453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-01T13:00:13Z

Weaknesses