Out of Bounds Read Vulnerability in MediaTek CCCI Product
CVE-2026-20476

5.5MEDIUM

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
3 August 2026

What is CVE-2026-20476?

A potential out of bounds read vulnerability exists in MediaTek's CCCI that could lead to a local denial of service. This flaw arises from a lack of necessary bounds checks, requiring user execution privileges for exploitation, although user interaction is not needed. Affected users are advised to apply the patch identified as ALPS10981532 to mitigate this issue, ensuring system security and stability.

Affected Version(s)

MediaTek chipset MT6813

MediaTek chipset MT6986

MediaTek chipset MT6988

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.