Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-20532

Quick assessment

Affected
MediaTek, Inc. MediaTek chipset
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 apu 模块中,由于双重释放(double free)问题,可能导致应用程序崩溃。这可能引发本地拒绝服务(DoS)漏洞,攻击者无需获得额外的执行权限即可利用该漏洞。利用此漏洞不需要用户交互。补丁编号:ALPS11249024;问题编号:MSV-9168。

AI Predicted 5.3 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-20532

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In apu, there is a possible application crash due to double free. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249024; Issue ID: MSV-9168.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
双重释放
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MediaTek, Inc. MediaTek chipset MT6899 -

II. Public POCs for CVE-2026-20532

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-20532

请登录查看更多情报信息。

Other References for CVE-2026-20532 (1)

Same Patch Batch · MediaTek, Inc. · 2026-10-05 · 31 CVEs total

CVE-2026-20544 联发科本地权限提升漏洞
CVE-2026-20519 高通调制解调器越界写入导致远程提权
CVE-2026-20520 联发基带漏洞:越界写入致权限提升
CVE-2026-20586 联发科vdec越界写漏洞
CVE-2026-20589 Venc因类型混淆致越界写,可致提权
CVE-2026-20521 Android Video HAL未检查边界致权限提升漏洞
CVE-2026-20522 Neuropilot越界写入漏洞
CVE-2026-20523 Neuropilot越界写入漏洞导致本地权限提升
CVE-2026-20524 apupro 内存错误致本地权限提升
CVE-2026-20525 MOLY Modem输入验证缺陷致远程DoS漏洞
CVE-2026-20526 展讯Modem越界写入致提权漏洞
CVE-2026-20527 Modem越界检查缺失致远程拒绝服务漏洞
CVE-2026-20579 Vdec类型混淆致越界写入漏洞
CVE-2026-20587 mtee系统权限提升漏洞(类型混淆)
CVE-2026-20588 mtee提权漏洞
CVE-2026-20543 展讯Modem逻辑错误致信息泄露漏洞
CVE-2026-20528 联发科MTK驱动越界读写漏洞
CVE-2026-20529 联发科电池模块越界写入漏洞
CVE-2026-20530 联发科显示器越界写入漏洞(ALPS11292777)
CVE-2026-20531 Alps apu 使用-after-free 漏洞导致权限提升

Showing top 20 of 31 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-20532

No comments yet


Leave a comment