Out of Bounds Read Vulnerability in MediaTek Modem
CVE-2026-20538

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20538?

A vulnerability in MediaTek's modem allows for an out of bounds read due to a lack of necessary permission checks. This flaw can be exploited by an attacker through a rogue base station, leading to a potential remote denial of service scenario without requiring user involvement or additional execution privileges. A patch has been issued to address this security concern. For more details, refer to the MediaTek security bulletin.

Affected Version(s)

MediaTek chipset MT2716

MediaTek chipset MT2735

MediaTek chipset MT2737

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.