Out-of-Bounds Read in ccci Affects MediaTek Products
CVE-2026-20490

4.4MEDIUM

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
3 August 2026

What is CVE-2026-20490?

The ccci vulnerability presents a risk of an out-of-bounds read due to insufficient bounds checking. This flaw may allow a malicious actor, who has already gained System privilege, to execute a local denial of service attack. Notably, user interaction is not required for the exploitation of this vulnerability, which underscores the urgency of applying the latest security patches to protect affected systems.

Affected Version(s)

MediaTek chipset MT6813

MediaTek chipset MT6982VB

MediaTek chipset MT6986

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.