Out of Bounds Write Vulnerability in Mediatek Modem
CVE-2026-20434
7.5HIGH
What is CVE-2026-20434?
A potential vulnerability has been identified in the Mediatek modem that allows for an out of bounds write due to a missing bounds check. If a user equipment (UE) connects to a rogue base station controlled by an attacker, this vulnerability may be exploited to escalate privileges remotely. While user interaction is necessary for the attack to occur, this flaw can pose a significant security threat if not promptly addressed. The recommended patch ID for remediation is MOLY00782946.
Affected Version(s)
MediaTek chipset MT2735
MediaTek chipset MT2737
MediaTek chipset MT6739
