Junglewise Threat Intelligence

CVE-2026-20432: MediaTek Chipset out of bounds write in Modem

CVE-2026-20432 · Severity: high · CVSS 8 · Published 2026-04-07

Executive brief

A security vulnerability exists in the modem software of several MediaTek chipsets used in mobile devices. If a user's device connects to a malicious cellular base station controlled by an attacker, the attacker could gain unauthorized control or elevated privileges on the device. This could lead to the theft of sensitive data or a complete compromise of the mobile device's security.

Technical details

An out-of-bounds (OOB) write vulnerability exists in the MediaTek Modem firmware due to insufficient validation of input data (missing bounds check). The vulnerability is exploitable via an adjacent network vector if a User Equipment (UE) device connects to a rogue base station controlled by an attacker. While the attack requires user interaction to initiate the connection or trigger the vulnerable state, it requires no additional execution privileges. Successful exploitation can lead to remote escalation of privilege (EoP) on the modem subsystem. MediaTek has released a patch under ID MOLY01406170 to address this issue.

Affected products

  • MediaTek, Inc. MediaTek chipset MT2735, MT2737, MT6779, MT6781, MT6783, MT6785, MT6789, MT6813, MT6815, MT6833, MT6835, MT6853, MT6855, MT6873, MT6875, MT6877, MT6878, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6896, MT6897, MT6899, MT6980, MT6983, MT6985, MT6989, MT6990, MT6991, MT6993, MT8668, MT8673, MT8675, MT8676, MT8678, MT8755, MT8771, MT8775, MT8781, MT8789

Timeline

  • 2026-04-07: advisory: Initial publication of the MediaTek security bulletin

References