Description
In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249062; Issue ID: MSV-9171.
Published: 2026-10-05
Score: n/a
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from a missing bounds check in the neuropilot component of MediaTek chipsets, allowing an out‑of‑bounds write. This flaw can corrupt memory and give an attacker local escalation of privilege without needing additional execution rights. Because no user interaction is required, any process with access to the affected component can exploit the issue, potentially compromising device integrity.

Affected Systems

MediaTek chipsets are affected. The vendor does not list specific firmware or hardware revisions in the advisory, so affected versions are unknown at this time; users should verify that their device is running an unsupported firmware version that lacks the patch.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in CISA KEV. Nonetheless, the defect presents a high risk, as it enables local privilege escalation. The likely attack vector is local exploitation of the neuropilot component; the exploitation requires no user interaction but does not need elevated permissions to trigger the out‑of‑bounds write.

Generated by OpenCVE AI on October 5, 2026 at 03:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the MediaTek patch identified by ALPS11249062 to eliminate the missing bounds check.
  • Temporarily disable or restrict the execution of the neuropilot component until the patch is successfully applied.
  • Monitor system logs for abnormal memory access errors and enforce device isolation from untrusted inputs during the remediation period.

Generated by OpenCVE AI on October 5, 2026 at 03:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Leading to Local Privilege Escalation in MediaTek Chipset

Mon, 05 Oct 2026 02:15:00 +0000

Type Values Removed Values Added
Description In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249062; Issue ID: MSV-9171.
Weaknesses CWE-787
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-10-05T01:39:51.593Z

Reserved: 2025-11-03T01:30:59.033Z

Link: CVE-2026-20523

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T02:16:50.917

Modified: 2026-10-05T02:16:50.917

Link: CVE-2026-20523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T03:30:14Z

Weaknesses