A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2023-20726

CVE-2023-20726: Yocto mnld GPS Information Disclosure Flaw

CVE-2023-20726 is an information disclosure vulnerability in Linuxfoundation Yocto's mnld component that exposes GPS location data due to missing permission checks. This article covers technical details, affected systems, and patches.

Updated: May 15, 2026

CVE-2023-20726 Overview

CVE-2023-20726 is an information disclosure vulnerability in the MediaTek mnld (MNL daemon) component, which manages GNSS and location services on MediaTek chipsets. The flaw stems from a missing permission check that allows a local, low-privileged application to read GPS location data without holding the required Android location permissions. Exploitation requires no user interaction and no additional execution privileges beyond a local app context. The issue affects a wide range of MediaTek-based Android devices, as well as embedded platforms shipping the MediaTek stack on Yocto, RDK-B, and OpenWrt. MediaTek issued patches tracked as ALPS07735968 and ALPS07884552 in its May 2023 Product Security Bulletin.

Critical Impact

A local app without location permissions can read GPS coordinates from mnld, enabling silent geolocation tracking of the device user.

Affected Products

  • MediaTek chipsets including MT6580, MT6739, MT6761–MT6896, MT6980/MT6980D, MT6983, MT6985, MT6990, MT2731/MT2735/MT2737, and the MT8xxx series
  • Google Android 11.0, 12.0, and 13.0 builds running the vulnerable MediaTek mnld daemon
  • Embedded platforms: Linux Foundation Yocto 2.6 and 3.3, RDK-B 2022q3, OpenWrt 19.07.0 and 21.02.0

Discovery Timeline

  • 2023-05-15 - CVE-2023-20726 published to the National Vulnerability Database (NVD)
  • May 2023 - MediaTek releases patches ALPS07735968 and ALPS07884552 in the May 2023 Product Security Bulletin
  • 2025-01-24 - Last updated in NVD database

Technical Details for CVE-2023-20726

Vulnerability Analysis

The mnld daemon is the MediaTek Modem/Navigation Location daemon that brokers GNSS data between the modem and Android location services. The vulnerability is classified under [CWE-862: Missing Authorization]. A code path in mnld exposes GPS location data to local callers without verifying that the caller holds the ACCESS_FINE_LOCATION or ACCESS_COARSE_LOCATION permission enforced by the Android framework.

Because mnld runs as a system-level service with direct access to GNSS hardware, any application that can communicate with the daemon over its local IPC interface can retrieve coordinates that should be gated by the Android permission model. The result is a confidentiality breach limited to location data, with no impact on integrity or availability.

Root Cause

The root cause is an authorization gap in mnld: the daemon trusts local clients without consulting the Android permission manager before returning location fixes. Patch IDs ALPS07735968 and ALPS07884552 (the latter applying specifically to MT6880, MT6890, MT6980, MT6980D, and MT6990) add the missing permission validation before location data is returned to the caller.

Attack Vector

Exploitation is local. A malicious or curious Android app installed on the device, with no declared location permissions, opens the IPC channel exposed by mnld and issues a request for current location. Because the daemon does not validate the caller's permissions, it responds with live GPS coordinates. No user prompt is displayed, and the activity does not appear in Android's location access indicators tied to the framework permission model. The vulnerability mechanism is described in the MediaTek advisory; no public proof-of-concept code is available.

Detection Methods for CVE-2023-20726

Indicators of Compromise

  • Untrusted third-party apps with no declared ACCESS_FINE_LOCATION or ACCESS_COARSE_LOCATION permissions that nonetheless open sockets or binder channels exposed by mnld
  • Anomalous IPC traffic to mnld originating from non-system UIDs
  • Apps that exfiltrate latitude/longitude values over the network despite having no location permission entitlements in their manifest

Detection Strategies

  • Audit Android package manifests on managed fleets for apps that access location-related IPC endpoints without declaring location permissions
  • Inspect device logs (logcat, dmesg) for mnld client connections from unexpected UIDs or package names
  • Use mobile threat defense or EDR telemetry to flag processes reading from GNSS-related device nodes outside the documented Android Location Services chain

Monitoring Recommendations

  • Enroll MediaTek-based Android devices in a mobile device management (MDM) platform and monitor patch level against the May 2023 MediaTek Security Bulletin
  • Track installation of sideloaded APKs on corporate devices, as the attack requires local app installation
  • Correlate outbound network flows containing geolocation payloads with the originating app's declared permissions

How to Mitigate CVE-2023-20726

Immediate Actions Required

  • Apply the MediaTek security patch corresponding to your chipset by updating to a firmware build that includes ALPS07735968 or ALPS07884552 as published in the MediaTek Security Bulletin - May 2023
  • Verify the Android security patch level on managed devices and require the May 2023 or later patch level for fleet compliance
  • Restrict sideloading of untrusted apps on MediaTek-based devices until patches are deployed

Patch Information

MediaTek addressed the issue with Patch IDs ALPS07735968 and ALPS07884552. The second patch applies specifically to MT6880, MT6890, MT6980, MT6980D, and MT6990. Device OEMs integrate these patches into their Android security maintenance releases. Refer to the MediaTek Security Bulletin - May 2023 for the full chipset and Issue ID matrix.

Workarounds

  • Limit app installation to vetted sources such as Google Play and enforce Play Protect on managed devices
  • Use Android enterprise work profiles to isolate untrusted applications from sensitive workflows
  • Where firmware updates are unavailable, disable or restrict access to applications that do not require GNSS functionality and monitor location-sensitive workflows on alternate devices

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeInformation Disclosure

  • Vendor/TechLinuxfoundation Yocto

  • SeverityLOW

  • CVSS Score3.3

  • EPSS Probability0.02%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityNone
  • CWE References
  • CWE-862
  • Vendor Resources
  • MediaTek Security Bulletin - May 2023
  • Related CVEs
  • CVE-2026-20435: Yocto Information Disclosure Vulnerability

  • CVE-2025-61611: Linuxfoundation Yocto DOS Vulnerability

  • CVE-2025-20765: Linuxfoundation Yocto DOS Vulnerability

  • CVE-2024-20148: Linuxfoundation Yocto RCE Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English