Executive brief
A vulnerability in certain MediaTek chipsets could allow an attacker to crash a mobile device's modem, leading to a loss of cellular connectivity. This occurs when a device connects to a malicious base station (rogue cell tower) controlled by the attacker. An exploit would result in a denial of service, preventing the user from making calls or using mobile data until the system is recovered.
Technical details
A logic error in the MediaTek modem firmware (CWE-770) leads to a system crash when the User Equipment (UE) interacts with a rogue base station. The vulnerability is exploitable via an adjacent network vector without requiring authentication or user interaction. An attacker in physical proximity can deploy a rogue base station to trigger a remote denial of service (DoS) on affected devices. MediaTek has released Patch ID MOLY01106496 to address this issue across multiple chipset models including MT68xx, MT69xx, and MT8xxx series.
Affected products
- MediaTek MT6813
- MediaTek MT6815
- MediaTek MT6835
- MediaTek MT6878
- MediaTek MT6897
- MediaTek MT6899
- MediaTek MT6986
- MediaTek MT6991
- MediaTek MT6993
- MediaTek MT8668
- MediaTek MT8676
- MediaTek MT8678
- MediaTek MT8755
- MediaTek MT8775
- MediaTek MT8792
- MediaTek MT8793
- MediaTek MT8863
- MediaTek MT8873
- MediaTek MT8883
Timeline
- 2026-04-07: advisory: MediaTek published the security bulletin
- 2026-04-07: disclosed: CVE published to NVD