Out of Bounds Write Vulnerability in HEVC Decoder of MediaTek Products
CVE-2026-20464

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
3 August 2026

What is CVE-2026-20464?

The HEVC decoder in MediaTek products contains an out of bounds write vulnerability that can be triggered by an integer overflow. If successfully exploited, this flaw could allow an attacker to escalate privileges without requiring user interaction once they have gained system-level access. Organizations should ensure they apply the relevant patches to protect their systems from potential exploitation.

Affected Version(s)

MediaTek chipset MT6761

MediaTek chipset MT8766

MediaTek chipset MT8768

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.