Out of Bounds Write in TFA Affects MediaTek Products
CVE-2026-20472
Currently unrated
What is CVE-2026-20472?
The TFA component from MediaTek is susceptible to an out of bounds write due to insufficient bounds checking. This vulnerability allows a malicious actor, with system privileges, to orchestrate a local denial of service. Notably, the exploitation does not require user interaction, posing significant risks for systems leveraging affected versions of TFA. Affected parties are strongly advised to implement the necessary patches to mitigate the risks associated with this vulnerability.
Affected Version(s)
MediaTek chipset MT6982VB
MediaTek chipset MT6986
MediaTek chipset MT6986D
