Out of Bounds Write Vulnerability in MediaTek Products
CVE-2026-20530

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20530?

This vulnerability presents an out of bounds write issue within MediaTek products, stemming from a missing bounds check during data display. Attackers with system privilege can exploit this flaw to escalate their access locally, enhancing their control over the affected system. Notably, no user interaction is necessary for exploitation, amplifying the risk for environments utilizing MediaTek solutions. To mitigate this vulnerability, users are encouraged to apply the latest security patch identified as ALPS11292777.

Affected Version(s)

MediaTek chipset MT2718

MediaTek chipset MT6991

MediaTek chipset MT6993

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.