ZeroHour

CVE-2026-20516

PoC mass

Local denial of service via confused deputy in MediaTek MiracastService

CVSS 3.1
5.5 medium
EPSS
<1%p1
Published
()
Modified
AI analysis

CVE-2026-20516 is a confused-deputy flaw in the MiracastService component of MediaTek device firmware that a local process running with user-level privileges can abuse to cause a denial of service. It is triggered by local execution on the device, requires no user interaction, and the CVSS vector indicates availability-only impact (high) with no confidentiality or integrity loss, despite the advisory describing it as a possible escalation of privilege. Affected devices are those running MediaTek firmware containing the vulnerable MiracastService component — the DTV patch identifier indicates MediaTek-powered digital TV/smart TV platforms are in scope. The affected firmware version range is not published in the available data. As of now the flaw is not in CISA KEV, EPSS is low (0.1% probability of exploitation in 30 days), one public proof-of-concept reference exists on GitHub, and no confirmed in-the-wild exploitation is reported.

What to do: Obtain firmware/OTA updates for MediaTek-based devices (especially smart TVs) from your device or TV vendor, looking for releases that incorporate MediaTek patch IDs ALPS11060069 / DTV04881615 or reference this CVE. Because exploitation requires local code execution with user privileges, avoid installing untrusted apps on affected TVs/devices as an interim mitigation. No network-level mitigation is indicated since the flaw is not remotely exploitable.

Affected
MediaTek MiracastService component in MediaTek device firmware (including DTV/smart TV platforms per patch tracking)
Estimated exposure
massplausibly millions of devices (MediaTek chipsets power a large share of smart TVs and Android devices; the affected firmware version range is undisclosed) — MediaTek DTV and Android chipsets ship in very high volumes across many TV and device brands and MiracastService is part of that firmware stack, but because the advisory publishes no affected version range, this is a coarse upper-bound…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11060069 / DTV04881615; Issue ID: MSV-7882.

Weakness
CWE-926
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.