CVE-2026-20516
PoC massLocal denial of service via confused deputy in MediaTek MiracastService
CVE-2026-20516 is a confused-deputy flaw in the MiracastService component of MediaTek device firmware that a local process running with user-level privileges can abuse to cause a denial of service. It is triggered by local execution on the device, requires no user interaction, and the CVSS vector indicates availability-only impact (high) with no confidentiality or integrity loss, despite the advisory describing it as a possible escalation of privilege. Affected devices are those running MediaTek firmware containing the vulnerable MiracastService component — the DTV patch identifier indicates MediaTek-powered digital TV/smart TV platforms are in scope. The affected firmware version range is not published in the available data. As of now the flaw is not in CISA KEV, EPSS is low (0.1% probability of exploitation in 30 days), one public proof-of-concept reference exists on GitHub, and no confirmed in-the-wild exploitation is reported.
What to do: Obtain firmware/OTA updates for MediaTek-based devices (especially smart TVs) from your device or TV vendor, looking for releases that incorporate MediaTek patch IDs ALPS11060069 / DTV04881615 or reference this CVE. Because exploitation requires local code execution with user privileges, avoid installing untrusted apps on affected TVs/devices as an interim mitigation. No network-level mitigation is indicated since the flaw is not remotely exploitable.
| MediaTek MiracastService component in MediaTek device firmware (including DTV/smart TV platforms per patch tracking) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11060069 / DTV04881615; Issue ID: MSV-7882.
- Weakness
- CWE-926
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.