Executive brief
A vulnerability exists in the modem component of several MediaTek chipsets used in mobile devices. If a device connects to a malicious base station controlled by an attacker, it could cause the modem to crash, leading to a total loss of cellular connectivity. This is a denial-of-service attack that does not require any user interaction or special permissions on the device.
Technical details
An improper input validation vulnerability exists in the MediaTek Modem firmware. An attacker can exploit this by operating a rogue base station (eNodeB/gNodeB) that sends malformed or unexpected inputs to a connecting User Equipment (UE). Successful exploitation results in a system crash of the modem component, causing a denial of service. No additional execution privileges or user interactions are required for the attack. MediaTek has released a patch under ID MOLY01816800 to address this issue.
Affected products
- MediaTek, Inc. MediaTek chipset MT2716, MT2735, MT2737, MT6739, MT6761, MT6762, MT6763, MT6765, MT6767, MT6768, MT6769, MT6771, MT6779, MT6781, MT6783, MT6785, MT6789, MT6813, MT6833, MT6835, MT6853, MT6855, MT6858, MT6873, MT6875, MT6877, MT6878, MT6879, MT6880, MT6881, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6896, MT6897, MT6899, MT6980, MT6982, MT6983, MT6985, MT6986, MT6986D, MT6988
Timeline
- 2026-07-01: advisory
- 2026-07-01: disclosed