Heap Buffer Overflow in Audio HAL of MediaTek Products
CVE-2026-20478
Currently unrated
What is CVE-2026-20478?
A vulnerability exists in the Audio HAL of MediaTek products that allows for a heap buffer overflow. This issue may lead to a local denial of service, requiring user execution privileges for exploitation. The vulnerability is primarily linked to the Audio Hardware Abstraction Layer, where improper memory management could lead to unexpected behavior. No user interaction is necessary for an attacker to exploit this vulnerability, making it a potential risk for affected devices. Immediate action is advised by applying the relevant patches identified by Patch ID: ALPS10981454 for certain models and AUTO00851293 for others.
Affected Version(s)
MediaTek chipset MT2735
MediaTek chipset MT2737
MediaTek chipset MT6880
