Out of Bounds Write Vulnerability in MediaTek Modem
CVE-2026-20519

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20519?

A vulnerability exists in MediaTek modem components that allows an attacker to exploit an out of bounds write condition. This can occur when a user equipment (UE) connects to a malicious base station controlled by the attacker. Once connected, the attacker may gain unauthorized privilege escalation without requiring additional execution privileges or user interaction. The issue is attributed to a lack of proper bounds checking within the modem's software, rendering it susceptible to such attacks. A patch is available to address this serious security flaw.

Affected Version(s)

MediaTek chipset MT2716

MediaTek chipset MT2735

MediaTek chipset MT2737

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.