Out of Bounds Write and Read Vulnerability in MediaTek Products
CVE-2026-20528

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20528?

A vulnerability in MediaTek's ccci component allows for an out of bounds write and read, stemming from a missing bounds check. This flaw can result in local information disclosure, memory corruption, crashes, or even privilege escalation if a malicious actor has gained System privileges. User interaction is required for successful exploitation, highlighting the importance of applying the necessary security patches as outlined in MediaTek's product security bulletin.

Affected Version(s)

MediaTek chipset MT2735

MediaTek chipset MT2737

MediaTek chipset MT6813

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.