Description
In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00833804; Issue ID: MSV-6741.
Published: 2026-08-03
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the apusys component of MediaTek chipsets, where a confused deputy flaw can be abused to elevate the privileges of a local attacker. If an actor already has System privilege, the flaw can be triggered without any additional user interaction, granting higher levels of access and potentially full control over the device. The weakness is categorized as CWE-787, indicating a buffer over-read or similar memory corruption issue that permits upward privilege escalation.

Affected Systems

Affected products are MediaTek, Inc. MediaTek chipset devices. No specific version or build information was supplied in the advisory; all firmware or software that incorporates the vulnerable apusys module may be at risk.

Risk and Exploitability

Because the flaw requires pre‑existing System privileges, exploitation is limited to users who have already compromised the device at a high privilege level. No remote attack vector or user interaction is needed. The CVSS score of 6 indicates moderate severity. The EPSS score is < 1%, and the vulnerability is not currently listed in CISA’s KEV catalog, suggesting that widespread, active attacks may not yet be documented. Nonetheless, once the initial compromise is achieved, the flaw permits a rapid elevation of privileges, making the risk significant for any device exposed to local adversaries.

Generated by OpenCVE AI on August 4, 2026 at 10:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official MediaTek patch identified as AUTO00833804 to all affected devices.
  • Revoke unnecessary System privileges from local applications and restrict administrative rights to essential services only.
  • Implement network segmentation and least privilege policies to reduce the likelihood that a local attacker can gain System-level access in the first place.

Generated by OpenCVE AI on August 4, 2026 at 10:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Confused Deputy in MediaTek Chipset

Mon, 03 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Confused Deputy in MediaTek Chipset

Mon, 03 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00833804; Issue ID: MSV-6741.
Weaknesses CWE-787
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-08-05T03:56:41.807Z

Reserved: 2025-11-03T01:30:59.015Z

Link: CVE-2026-20468

cve-icon Vulnrichment

Updated: 2026-08-03T19:39:46.050Z

cve-icon NVD

Status : Received

Published: 2026-08-03T03:16:41.683

Modified: 2026-08-05T05:16:51.080

Link: CVE-2026-20468

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:00:07Z

Weaknesses