Out of Bounds Write Vulnerability in MediaTek Modem
CVE-2026-20526

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20526?

In MediaTek's modem, a vulnerability exists that allows for an out of bounds write due to inadequate bounds checking. This flaw enables an attacker controlling a rogue base station to escalate privileges remotely if a user equipment (UE) connects to it. While the exploitation requires user interaction, the risks involved can lead to significant security breaches. A patch has been issued to address this issue, identified by Patch ID MOLY01898195 and Issue ID MSV-8906.

Affected Version(s)

MediaTek chipset MT2716

MediaTek chipset MT2735

MediaTek chipset MT2737

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.