Heap Buffer Overflow Vulnerability in MediaTek Sec Boot Products
CVE-2026-20466
Currently unrated
What is CVE-2026-20466?
A heap buffer overflow vulnerability exists in MediaTek's sec boot that may allow local escalation of privilege. An attacker with physical access to the device can exploit this flaw without requiring additional execution privileges. Notably, user interaction is not essential for the exploitation, making it a significant security concern. Mitigation requires the deployment of specific patches identified as AUTO00845351 for the MT2737 and ALPS11072643 for the MT6880, MT6890, and MT6990 models. Users are strongly advised to implement these updates promptly to safeguard their systems.
Affected Version(s)
MediaTek chipset MT2737
MediaTek chipset MT6880
MediaTek chipset MT6890
