Information Disclosure Vulnerability in TFA by MediaTek
CVE-2026-20484

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
3 August 2026

What is CVE-2026-20484?

The TFA component of MediaTek products is susceptible to a potential information disclosure issue caused by the absence of a proper permission check. This vulnerability may allow a malicious actor, who has acquired system-level privileges, to access sensitive information without requiring any user interaction. The issue underscores the importance of applying security patches, as detailed in the provided bulletin.

Affected Version(s)

MediaTek chipset MT6739

MediaTek chipset MT6761

MediaTek chipset MT6765

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.