Out of Bounds Read Vulnerability in MediaTek Modem Products
CVE-2026-20479

7.5HIGH

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
3 August 2026

What is CVE-2026-20479?

In MediaTek modem products, a significant vulnerability has been identified that allows for a possible out of bounds read. This can occur due to a missing bounds check, posing a risk when a user equipment connects to a malicious base station controlled by an attacker. The exploitation of this vulnerability does not require any execution privileges or user interaction, making it a potential vector for remote denial of service attacks. Immediate action and patching are recommended to protect affected systems.

Affected Version(s)

MediaTek chipset MT2735

MediaTek chipset MT6833

MediaTek chipset MT6853

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.