Out of Bounds Write in vdec Affects MediaTek Products
CVE-2026-20586

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20586?

A vulnerability has been identified in MediaTek's vdec component, where a missing bounds check can lead to an out of bounds write. This issue could potentially allow remote escalation of privilege, requiring user interaction for exploitation. It is crucial for users and administrators of affected MediaTek products to apply the necessary patches to mitigate the risks associated with this vulnerability, as detailed in Patch ID ALPS11383899.

Affected Version(s)

MediaTek chipset MT2718

MediaTek chipset MT6768

MediaTek chipset MT6769

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.