Out of Bounds Write Vulnerability in MediaTek Products
CVE-2026-20425

6.7MEDIUM

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
2 March 2026

What is CVE-2026-20425?

A vulnerability exists within MediaTek's display functionality due to a missing bounds check, which could allow a local escalation of privilege. If a malicious actor has system privileges, they could exploit this flaw without requiring user interaction. Addressing this issue in the form of a patch (ID: ALPS10320471; Issue ID: MSV-5539) is essential to safeguard affected devices and maintain user security.

Affected Version(s)

MediaTek chipset MT6739

MediaTek chipset MT6761

MediaTek chipset MT6765

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.