Description
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765.
Published: 2026-08-03
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The defect is a missing permission check within MediaTek’s geniezone component. A malicious actor who already holds System privilege can exploit this flaw to elevate privileges further without any user interaction. The core weakness is a failure to enforce an authorization boundary, allowing unauthorized privilege escalation.

Affected Systems

This vulnerability impacts MediaTek, Inc.’s MediaTek chipset family. No specific version range is disclosed in the advisory, so all models using the geniezone software are potentially affected. Users of these chipsets should consider the possibility of exploitation if the device can enter a System‑privileged state.

Risk and Exploitability

The CVSS score of 6.0 classifies this as a moderate‑severity vulnerability, while the EPSS score of < 1% suggests a low chance of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating that broad, automated exploitation is not currently known. The flaw is purely local and requires that the attacker already possesses System privilege or a means to acquire it. Consequently, direct remote exploitation is unlikely; however, any local compromise that grants System access could be leveraged to hijack the device’s privileges.

Generated by OpenCVE AI on August 4, 2026 at 10:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Mediatek patch ALPS10900493 on all affected devices
  • Update the device firmware to the latest vendor release that incorporates the fix
  • Restrict or monitor system‑level access to prevent accidental gain of System privilege

Generated by OpenCVE AI on August 4, 2026 at 10:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mt6991
Mediatek mt6991 Firmware
Mediatek mt8768
Mediatek mt8768 Firmware
Mediatek mt8791t
Mediatek mt8791t Firmware
Mediatek mt8792
Mediatek mt8792 Firmware
Mediatek mt8796
Mediatek mt8796 Firmware
Mediatek mt8799
Mediatek mt8799 Firmware
Mediatek mt8873
Mediatek mt8873 Firmware
Mediatek mt8883
Mediatek mt8883 Firmware
Mediatek mt8893
Mediatek mt8893 Firmware
Mediatek mt8910
Mediatek mt8910 Firmware
CPEs cpe:2.3:h:mediatek:mt6991:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8792:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8799:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8873:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8883:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8893:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8910:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6991_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8768_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8791t_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8792_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8796_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8799_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8873_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8883_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8893_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8910_firmware:-:*:*:*:*:*:*:*
Vendors & Products Mediatek
Mediatek mt6991
Mediatek mt6991 Firmware
Mediatek mt8768
Mediatek mt8768 Firmware
Mediatek mt8791t
Mediatek mt8791t Firmware
Mediatek mt8792
Mediatek mt8792 Firmware
Mediatek mt8796
Mediatek mt8796 Firmware
Mediatek mt8799
Mediatek mt8799 Firmware
Mediatek mt8873
Mediatek mt8873 Firmware
Mediatek mt8883
Mediatek mt8883 Firmware
Mediatek mt8893
Mediatek mt8893 Firmware
Mediatek mt8910
Mediatek mt8910 Firmware

Tue, 04 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in MediaTek geniezone

Mon, 03 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765.
Weaknesses CWE-1287
References

Subscriptions

Mediatek Mt6991 Mt6991 Firmware Mt8768 Mt8768 Firmware Mt8791t Mt8791t Firmware Mt8792 Mt8792 Firmware Mt8796 Mt8796 Firmware Mt8799 Mt8799 Firmware Mt8873 Mt8873 Firmware Mt8883 Mt8883 Firmware Mt8893 Mt8893 Firmware Mt8910 Mt8910 Firmware
Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-08-05T03:56:57.948Z

Reserved: 2025-11-03T01:30:59.027Z

Link: CVE-2026-20498

cve-icon Vulnrichment

Updated: 2026-08-03T19:47:38.949Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T03:16:45.000

Modified: 2026-08-19T01:05:27.590

Link: CVE-2026-20498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:00:07Z

Weaknesses
  • CWE-1287

    Improper Validation of Specified Type of Input