Out of Bounds Write Vulnerability in imgsys by MediaTek
CVE-2026-20413
6.7MEDIUM
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 2 February 2026
What is CVE-2026-20413?
In imgsys, a security flaw allows for an out of bounds write due to inadequate bounds checking. This vulnerability could enable local privilege escalation for an attacker who has already gained system privileges. Exploiting this issue does not require user interaction, making it a significant risk for affected systems. Security updates are available to address this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MT6899, MT6991, MT8678, MT8793 Android 15.0
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
