Out of Bounds Read Vulnerability in MediaTek Modem
CVE-2026-20539

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20539?

A vulnerability in MediaTek's modem allows attackers to exploit an out of bounds read due to an insufficient bounds check. This can result in remote denial of service, particularly when a user equipment (UE) connects to a malicious base station controlled by an attacker. Notably, exploitation of this vulnerability does not require user interaction, raising concerns regarding device security when used in vulnerable configurations. The issue has been documented under Patch ID: MOLY01774038, Issue ID: MSV-8913. It's critical for users to remain vigilant and apply security updates promptly.

Affected Version(s)

MediaTek chipset MT2716

MediaTek chipset MT2735

MediaTek chipset MT2737

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.