CVE-2026-20491

MEDIUM

MediaTek Chipset - Out-of-bounds Write

Title source: rule
STIX 2.1

Description

In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.

Scores

CVSS v3 5.5
EPSS 0.0010
EPSS Percentile 1.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (5)
MediaTek, Inc./MediaTek chipset MT2735
MediaTek, Inc./MediaTek chipset MT2737
MediaTek, Inc./MediaTek chipset MT6890
MediaTek, Inc./MediaTek chipset MT6988
MediaTek, Inc./MediaTek chipset MT6990
Published Aug 03, 2026
Tracked Since Aug 03, 2026