Logic Error in Preloader Exposes Device Identifiers in MediaTek Products
CVE-2026-20435

4.6MEDIUM

What is CVE-2026-20435?

CVE-2026-20435 is a vulnerability found in MediaTek products, specifically related to a logic error within the preloader component. MediaTek is a key player in the semiconductor industry, providing chips that power a wide range of devices, including smartphones and IoT products. The vulnerability allows for the potential exposure of unique device identifiers, which can be detrimental to an organization because these identifiers can be used to track devices or infer user behavior. An attacker would not need elevated privileges or user interaction to exploit this weakness; they would only require physical access to the affected device. This presents a unique risk in environments where devices are not properly secured or monitored.

Potential Impact of CVE-2026-20435

  1. Information Disclosure: The primary impact of CVE-2026-20435 is the local disclosure of sensitive device identifiers. This could result in unauthorized access to device-specific information that can be misused for malicious purposes, such as tracking or identity impersonation.

  2. Increased Risk of Physical Attacks: The requirement for physical access means that devices could become targets for theft or tampering. If such an action were taken, attackers could exploit this vulnerability to extract sensitive data without the need for complex methods.

  3. Reputational Damage: Organizations utilizing MediaTek products may face reputational harm if they are unable to safeguard user information effectively. Exposed identifiers can lead to a loss of trust from consumers, especially if the disclosure leads to larger security incidents or data breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

MT2737, MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6813, MT6833, MT6853, MT6855, MT6877, MT6878, MT6879, MT6880, MT6885, MT6886, MT6890, MT6893, MT6895, MT6897, MT6983, MT6985, MT6989, MT6990, MT6993, MT8169, MT8186, MT8188, MT8370, MT8390, MT8676, MT8678, MT8696, MT8793 Android 14.0, 15.0, 16.0 / openWRT 21.02, 23.05 / Yocto 4.0 / RDK-B 22Q3, 24Q1 / Zephyr 3.7.0

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.