Heap Buffer Overflow in Audio HAL Affects MediaTek Devices
CVE-2026-20480

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
3 August 2026

What is CVE-2026-20480?

A vulnerability has been identified in MediaTek's Audio HAL, characterized by a heap buffer overflow that can permit a local denial of service. The exploitation of this flaw does not require user interaction, making it particularly critical for users. The vulnerability necessitates user execution privileges for successful exploitation, which may impact device functionality. MediaTek has issued patches identified by Patch ID ALPS10960023 and AUTO00851189 for various affected models. Users are strongly advised to apply the latest updates to mitigate potential risks.

Affected Version(s)

MediaTek chipset MT2735

MediaTek chipset MT2737

MediaTek chipset MT6880

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.