{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/android-tv/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":5.5,"id":"CVE-2026-20516"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MiracastService (included in V03.06037 and potentially other versions)"],"_cs_severities":["low"],"_cs_tags":["android","privilege-escalation","media-tek","android-tv"],"_cs_type":"advisory","_cs_vendors":["MediaTek","Changhong"],"content_html":"\u003cp\u003eCVE-2026-20516 describes a confused deputy vulnerability found in the MiracastService component (\u003ccode\u003ecom.mediatek.androidbox\u003c/code\u003e) within certain Android TV implementations. The service is incorrectly exported without access controls and possesses \u003ccode\u003eandroid.uid.system\u003c/code\u003e privileges. A local attacker can supply a malicious intent extra, \u003ccode\u003escreen_share\u003c/code\u003e, to the \u003ccode\u003eMiracastService\u003c/code\u003e via \u003ccode\u003eonStartCommand()\u003c/code\u003e. This forces the service to perform privileged actions, specifically the management of Wi-Fi Direct groups using \u003ccode\u003eWifiP2pManager.createGroup()\u003c/code\u003e, despite the caller lacking the necessary permissions. MediaTek acknowledged the flaw in its September 2026 security bulletin (MSV-7882). The vulnerability poses a risk of local denial of service and unauthorized state manipulation on impacted Android TV firmware.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains local code execution on an Android TV device.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the \u003ccode\u003ecom.mediatek.androidbox\u003c/code\u003e package and the \u003ccode\u003eMiracastService\u003c/code\u003e component.\u003c/li\u003e\n\u003cli\u003eAttacker constructs an Android intent targeting \u003ccode\u003eMiracastService\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker attaches the intent extra \u003ccode\u003e--ez screen_share false\u003c/code\u003e to the intent.\u003c/li\u003e\n\u003cli\u003eAttacker executes \u003ccode\u003eam startservice\u003c/code\u003e to invoke the exported, unprotected service.\u003c/li\u003e\n\u003cli\u003eThe service, running as \u003ccode\u003eandroid.uid.system\u003c/code\u003e, receives the intent and fails to validate the caller's authorization.\u003c/li\u003e\n\u003cli\u003eThe service executes the \u003ccode\u003ecreateGroup()\u003c/code\u003e method via \u003ccode\u003eWifiP2pManager\u003c/code\u003e, bypassing intended system constraints.\u003c/li\u003e\n\u003cli\u003eFinal objective: Successful manipulation of Wi-Fi Direct state, leading to denial of service of Miracast functionality.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows local attackers to disrupt legitimate Miracast service usage and manipulate system-level Wi-Fi Direct states. While the PoC demonstrates state manipulation and denial of service, it does not confirm arbitrary code execution or privilege escalation to root. The flaw affects Android TV devices using MediaTek chipsets, though the specific impact depends on OEM-provided firmware updates.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching based on the following:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eVerify firmware versions against the MediaTek patch identifiers \u003ccode\u003eALPS11060069\u003c/code\u003e or \u003ccode\u003eDTV04881615\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eDisable \u003ccode\u003eandroid:exported\u003c/code\u003e for components handling sensitive lifecycle operations in custom Android applications.\u003c/li\u003e\n\u003cli\u003eEnforce signature-level permissions for any component that must be externally accessible.\u003c/li\u003e\n\u003cli\u003eEnsure all service entry points perform explicit caller authorization checks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-11T09:29:56Z","date_published":"2026-09-11T09:29:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-20516/","summary":"An improperly exported MiracastService component on Android TV devices using MediaTek chipsets allows local attackers to manipulate Wi-Fi Direct states and cause denial of service via a confused deputy attack.","title":"Confused Deputy Vulnerability in MediaTek MiracastService (CVE-2026-20516)","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-20516/"}],"language":"en","title":"CraftedSignal Threat Feed - Android-Tv","version":"https://jsonfeed.org/version/1.1"}