Description
In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767.
Published: 2026-08-03
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In the MediaTek apusys component, a bounds check is missing, allowing a local attacker who already possesses system privileges to manipulate memory. This omission can lead to a full privilege escalation, granting the attacker complete control over the device. The weakness is classified as a Bounds Checking error (CWE-749).

Affected Systems

MediaTek, Inc. MediaTek chipset. The vulnerability is documented for devices using the apusys component and can be mitigated with firmware patch AUTO00837766, Issue ID MSV-6767. No specific version range is supplied in the advisory.

Risk and Exploitability

Exploitation requires the attacker to have local system privileges; no user interaction is needed. Because the EPSS score is <1% and the CVSS score of 6 indicates moderate severity, and the issue is not listed in the CISA KEV catalog, the overall exposure is considered moderate. An attacker with system access could overwrite critical kernel data structures via the missing bounds check, elevating their privileges to full device control.

Generated by OpenCVE AI on August 4, 2026 at 21:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the MediaTek firmware patch AUTO00837766 as soon as possible.
  • Restrict installation of applications that can acquire system privileges; enforce strict app‑signing policies.
  • If the apusys functionality is not essential, disable or limit its operation to reduce the attack surface.
  • Continuously monitor device logs for anomalous privilege‑escalation activity.

Generated by OpenCVE AI on August 4, 2026 at 21:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Missing Bounds Check in MediaTek apusys

Mon, 03 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Missing Bounds Check in MediaTek apusys

Mon, 03 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767.
Weaknesses CWE-749
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-08-05T03:56:40.671Z

Reserved: 2025-11-03T01:30:59.015Z

Link: CVE-2026-20467

cve-icon Vulnrichment

Updated: 2026-08-03T19:39:01.377Z

cve-icon NVD

Status : Received

Published: 2026-08-03T03:16:41.547

Modified: 2026-08-05T05:16:50.617

Link: CVE-2026-20467

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:00:07Z

Weaknesses
  • CWE-749

    Exposed Dangerous Method or Function