Out of Bounds Write Vulnerability in MediaTek Camera ISP
CVE-2026-20412

7.8HIGH

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
2 February 2026

What is CVE-2026-20412?

In the MediaTek Camera ISP, a vulnerability has been identified that allows an out of bounds write due to insufficient bounds checks. This issue poses a risk of local privilege escalation, provided that an attacker has already gained system privileges. The vulnerability is exploitable without requiring user interaction, making it particularly concerning. A patch has been issued to address this issue and enhance system security.

Affected Version(s)

MediaTek chipset MT6878

MediaTek chipset MT6879

MediaTek chipset MT6881

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.