Heap Buffer Overflow Vulnerability in MediaTek Sec Boot Products
CVE-2026-20466

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
3 August 2026

What is CVE-2026-20466?

A heap buffer overflow vulnerability exists in MediaTek's sec boot that may allow local escalation of privilege. An attacker with physical access to the device can exploit this flaw without requiring additional execution privileges. Notably, user interaction is not essential for the exploitation, making it a significant security concern. Mitigation requires the deployment of specific patches identified as AUTO00845351 for the MT2737 and ALPS11072643 for the MT6880, MT6890, and MT6990 models. Users are strongly advised to implement these updates promptly to safeguard their systems.

Affected Version(s)

MediaTek chipset MT2737

MediaTek chipset MT6880

MediaTek chipset MT6890

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.