Out of Bounds Write in TFA Affects MediaTek Products
CVE-2026-20472

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
3 August 2026

What is CVE-2026-20472?

The TFA component from MediaTek is susceptible to an out of bounds write due to insufficient bounds checking. This vulnerability allows a malicious actor, with system privileges, to orchestrate a local denial of service. Notably, the exploitation does not require user interaction, posing significant risks for systems leveraging affected versions of TFA. Affected parties are strongly advised to implement the necessary patches to mitigate the risks associated with this vulnerability.

Affected Version(s)

MediaTek chipset MT6982VB

MediaTek chipset MT6986

MediaTek chipset MT6986D

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.