Type Confusion Vulnerability in MediaTek Vdec
CVE-2026-20579

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20579?

A potential out of bounds write vulnerability has been identified in MediaTek's Vdec due to type confusion. This issue could allow a malicious actor to escalate privileges locally, especially if they have already gained system privileges. Notably, exploitation does not require user interaction, increasing the urgency for timely mitigations. The vulnerability is tracked under Patch ID ALPS11383899 and Issue ID MSV-9800.

Affected Version(s)

MediaTek chipset MT2718

MediaTek chipset MT6768

MediaTek chipset MT6769

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.