CVE-2026-20516
In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11060069 / DTV04881615; Issue ID: MSV-7882.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.09%
- CWE
- CWE-926
- Published
- 2026-09-07
- Last modified
- 2026-09-07
Affected products
- MediaTek, Inc. MediaTek chipset
- MediaTek, Inc. MediaTek chipset
- MediaTek, Inc. MediaTek chipset
- MediaTek, Inc. MediaTek chipset
- MediaTek, Inc. MediaTek chipset
- MediaTek, Inc. MediaTek chipset
- MediaTek, Inc. MediaTek chipset
- MediaTek, Inc. MediaTek chipset
Weakness type
Related vulnerabilities
- CVE-2026-44965 — Six Android App Widget configuration activities in the Datadog Android application are declared...
- CVE-2026-47363 — The launcher activity AppActivity in the Datadog Android application is declared...
- CVE-2026-47361 — BubbleChatActivity in the Datadog Android application is declared android:exported="true" with no...
- CVE-2026-18604 — textPlus Text Message and Call App com.gogii.textplus DialerActivity improper export of android application components
- CVE-2026-20470 — In Telephony, there is a possible information disclosure due to a missing permission check. This...
- CVE-2026-57848 — Stoat for Android Internal File Disclosure via Exported ShareTargetActivity URI Validation
- CVE-2026-12960 — An Improper Export of Android Application Components vulnerability in ASUS Router App allows a...
- CVE-2026-54318 — Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location