Description
In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11006447; Issue ID: MSV-7871.
Published: 2026-07-01
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap buffer overflow exists in the MediaTek Telephony component, which can corrupt heap memory. The flaw, identified as CWE‑122, enables a local attacker who already holds system privileges to potentially elevate privileges further, thereby compromising device security if exploited successfully.

Affected Systems

Any device that incorporates a MediaTek chipset with Telephony support is affected. The advisory does not specify firmware or OS versions, so all releases using the Telephony subsystem remain vulnerable until the vendor releases patch ALPS11006447 (MSV‑7871).

Risk and Exploitability

The CVSS score of 6.7 indicates moderate severity, while the EPSS score is below 1% and the vulnerability is not listed in CISA KEV. Exploitation does not require user interaction; an attacker with local system privileges can trigger the overflow by interacting with the Telephony subsystem to achieve further privilege escalation. Because the local system privilege is a prerequisite, the risk is confined to compromised local users.

Generated by OpenCVE AI on August 3, 2026 at 06:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the MediaTek vendor patch ALPS11006447 (Issue ID MSV-7871).
  • Restrict use of Telephony APIs and enforce strict access controls as a temporary containment measure.
  • Monitor system logs for anomalous Telephony activity.

Generated by OpenCVE AI on August 3, 2026 at 06:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in MediaTek Telephony Enables Local Privilege Escalation

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title MediaTek Telephony Heap Buffer Overflow Leading to Local Privilege Escalation

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title MediaTek Telephony Heap Buffer Overflow Leading to Local Privilege Escalation

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in MediaTek Telephony Component Enables Local Privilege Escalation

Wed, 15 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in MediaTek Telephony Component Enables Local Privilege Escalation

Tue, 14 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in MediaTek Telephony Leading to Local Privilege Escalation

Mon, 13 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in MediaTek Telephony Leading to Local Privilege Escalation

Sun, 12 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title MediaTek Telephony Heap Overflow Enabling Local Privilege Escalation

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title MediaTek Telephony Heap Overflow Enabling Local Privilege Escalation

Fri, 10 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title MediaTek Telephony Heap Overflow Enables Local Privilege Escalation

Thu, 09 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title MediaTek Telephony Heap Overflow Enables Local Privilege Escalation

Wed, 08 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Telephony Component Enables Local Privilege Escalation

Tue, 07 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Telephony Component Enables Local Privilege Escalation

Mon, 06 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Telephony Leading to Local Privilege Escalation

Sun, 05 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Telephony Leading to Local Privilege Escalation

Sun, 05 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in MediaTek Telephony Subsystem Enables Local Privilege Escalation

Sat, 04 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in MediaTek Telephony Subsystem Enables Local Privilege Escalation

Sat, 04 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Telephony Enables Local Privilege Escalation

Fri, 03 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Telephony Enables Local Privilege Escalation

Fri, 03 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Memory Corruption in Telephony Enables Local Privilege Escalation

Thu, 02 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Memory Corruption in Telephony Enables Local Privilege Escalation

Thu, 02 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in MediaTek Telephony Enables Local Privilege Escalation

Thu, 02 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in MediaTek Telephony Enables Local Privilege Escalation

Thu, 02 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title MediaTek Telephony Heap Buffer Overflow Leading to Local Privilege Escalation

Wed, 01 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title MediaTek Telephony Heap Buffer Overflow Leading to Local Privilege Escalation

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in MediaTek Telephony Subsystem Enables Local Privilege Escalation

Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in MediaTek Telephony Subsystem Enables Local Privilege Escalation

Wed, 01 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11006447; Issue ID: MSV-7871.
Weaknesses CWE-122
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-07-02T03:55:17.558Z

Reserved: 2025-11-03T01:30:59.014Z

Link: CVE-2026-20462

cve-icon Vulnrichment

Updated: 2026-07-01T10:36:28.557Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T06:15:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow