Heap Buffer Overflow Vulnerability in MediaTek Products
CVE-2026-20501

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
7 September 2026

What is CVE-2026-20501?

A heap buffer overflow vulnerability exists in the vdec component of MediaTek products, which may allow attackers to perform local privilege escalation without requiring additional execution privileges. This vulnerability can be exploited without any user interaction. The issue has been tracked under Patch ID: ALPS11262030 and Issue ID: MSV-9197. It is crucial for users of affected versions to apply the latest patches to mitigate potential security risks.

Affected Version(s)

MediaTek chipset MT2718

MediaTek chipset MT6580

MediaTek chipset MT6739

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.