Out of Bounds Write Vulnerability in MediaTek PCIe Products
CVE-2026-20416
7.2HIGH
What is CVE-2026-20416?
A vulnerability exists in MediaTek's PCIe products due to a missing bounds check, leading to potential out of bounds write scenarios. This flaw could allow a malicious actor, who has already secured system privilege, to escalate their access without requiring user interaction. Immediate patching is recommended to mitigate risks associated with this vulnerability as detailed in the product security bulletin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MT6991, MT6993, MT8188, MT8678 Android 15.0, 16.0
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
