Description
In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087540; Issue ID: MSV-8246.
Published: 2026-09-07
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

Audio HAL has an input validation flaw classified as CWE-307, which may allow a local user with system privileges to gain higher privileges. Exploitation requires no user interaction and can lead to code execution with elevated rights.

Affected Systems

Affected components are MediaTek chipsets used in devices. No specific firmware or chipset versions are listed in the advisory, so any device running the current Audio HAL without the mentioned patch is potentially vulnerable.

Risk and Exploitability

The CVSS score is 6.7, and the EPSS score is < 1%. The vulnerability is listed as a local privilege escalation that can be leveraged by a malicious actor who has already obtained system-level access. Because no user interaction is required, the risk is confined to local environments, and the vulnerability is not currently listed in the CISA KEV catalog. Apply the vendor patch ALPS11087540 as it resolves the issue.

Generated by OpenCVE AI on September 10, 2026 at 03:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the MediaTek patch identified as ALPS11087540 to update the Audio HAL component.
  • Ensure that the device firmware is updated to the latest version that incorporates this patch or newer releases.
  • Limit or disable audio services that rely on the vulnerable Audio HAL in environments where unnecessary, thereby reducing the attack surface.

Generated by OpenCVE AI on September 10, 2026 at 03:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title Audio HAL Improper Validation Enables Local Privilege Escalation on MediaTek Chipsets

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 07 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Audio HAL Improper Validation Enables Local Privilege Escalation on MediaTek Chipsets

Mon, 07 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087540; Issue ID: MSV-8246.
Weaknesses CWE-307
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-09-08T18:00:53.443Z

Reserved: 2025-11-03T01:30:59.030Z

Link: CVE-2026-20512

cve-icon Vulnrichment

Updated: 2026-09-07T10:25:34.047Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T02:17:19.923

Modified: 2026-09-08T18:37:41.047

Link: CVE-2026-20512

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T03:45:06Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts