Junglewise Threat Intelligence

CVE-2026-20460: MediaTek Chipset information disclosure in Modem

CVE-2026-20460 · Severity: info · Published 2026-07-01

Technologies: MediaTek Chipset. Vendors: MediaTek.

Executive brief

A vulnerability in the modem component of several MediaTek chipsets could allow an attacker to access sensitive information from a mobile device. To exploit this, an attacker must operate a rogue cellular base station that the target device connects to. This could lead to the unauthorized disclosure of data without requiring any interaction from the user.

Technical details

An information disclosure vulnerability exists in the MediaTek Modem component due to improper input validation. An attacker can exploit this by setting up a rogue base station (eNodeB/gNodeB) and tricking a User Equipment (UE) device into connecting to it. Once connected, the lack of proper validation allows for remote information disclosure from the modem. The vulnerability is tracked by MediaTek under Issue ID MSV-6788 and Patch ID MOLY01811421. No additional execution privileges or user interaction are required for exploitation.

Affected products

  • MediaTek, Inc. MediaTek chipset MT2735, MT2737, MT6779, MT6781, MT6783, MT6785, MT6789, MT6813, MT6833, MT6835, MT6853, MT6855, MT6858, MT6873, MT6875, MT6877, MT6878, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6896, MT6897, MT6899, MT6980, MT6983, MT6985, MT6986D, MT6988, MT6989, MT6990, MT6991, MT6993, MT8673, MT8675, MT8676, MT8678, MT8755, MT8765, MT8766, MT8766R, MT8768

Timeline

  • 2026-07-01: advisory: MediaTek published the security bulletin and NVD published the CVE record.

References

Related threats