In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.
References
| Link | Resource |
|---|---|
| https://www.mediatek.com/product-security-bulletin/August-2026 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
History
No history.
Information
Published : 2026-08-03 03:16
Updated : 2026-08-19 15:08
NVD link : CVE-2026-20495
Mitre link : CVE-2026-20495
CVE.ORG link : CVE-2026-20495
JSON object : View
Products Affected
mediatek
- mt7925
- mt7902
- mt7922
- mt7927_firmware
- mt7902_firmware
- mt7920_firmware
- mt7920
- mt7921
- mt7921_firmware
- mt7927
- mt7922_firmware
- mt7925_firmware
CWE
CWE-862
Missing Authorization
