Skip to content
MediaTekCVE-2026-20491

MediaTek chipset: out-of-bounds write

Medium5.5CVE-2026-20491 · Published Aug 3, 2026 · updated Aug 19, 2026

In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.

MediaTek advisory

Affected versions

PackageAffectedFixed in
MediaTek chipset
Product
<= MT2735No fix yet
<= MT2737No fix yet
<= MT6890No fix yet
<= MT6988No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
CISA (its enrichment of the CVE record)
Weakness
CWE-787

More MediaTek advisories

All MediaTek
Advisory
MediaTek chipset: privilege escalation
Medium6.0Aug 3
MediaTek chipset: out-of-bounds read
Medium4.4Aug 3
MediaTek chipset: race condition
Medium5.5Aug 3
MediaTek chipset: out-of-bounds write
Medium4.4Aug 3
MediaTek chipset: out-of-bounds read
Medium5.5Aug 3
MediaTek chipset: privilege escalation
High7.8Aug 3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.