Potential Out-of-Bounds Write Vulnerability in VENC by MediaTek
CVE-2026-20589

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20589?

The VENC product by MediaTek is affected by a vulnerability that enables an out-of-bounds write due to type confusion. This flaw poses a risk of local privilege escalation, particularly in scenarios where an attacker has already secured system-level privileges. Exploitation does not require any user interaction, making it a critical concern for users and administrators of the affected systems. For remediation, users are advised to apply the latest updates as outlined in the security bulletin.

Affected Version(s)

MediaTek chipset MT2718

MediaTek chipset MT6768

MediaTek chipset MT6769

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.