Executive brief
A vulnerability exists in the modem component of several MediaTek chipsets used in mobile devices. If a device connects to a malicious base station controlled by an attacker, it could cause the modem to crash or stop functioning. This results in a denial of service, preventing the user from making calls or using cellular data.
Technical details
An out-of-bounds write vulnerability exists in MediaTek Modem firmware due to a missing bounds check. The flaw is triggered when a User Equipment (UE) connects to a rogue base station controlled by an attacker. Exploitation does not require additional execution privileges or user interaction. Successful exploitation leads to a remote denial of service (DoS) of the modem component. MediaTek has released patches under IDs MOLY01267281 and MOLY01318201 to address this issue.
Affected products
- MediaTek MT2737
- MediaTek MT6813
- MediaTek MT6835
- MediaTek MT6858
- MediaTek MT6878
- MediaTek MT6879
- MediaTek MT6886
- MediaTek MT6895
- MediaTek MT6896
- MediaTek MT6897
- MediaTek MT6899
- MediaTek MT6980
- MediaTek MT6983
- MediaTek MT6985
- MediaTek MT6988
- MediaTek MT6989
- MediaTek MT6990
- MediaTek MT6991
- MediaTek MT6993
- MediaTek MT8673
- MediaTek MT8676
- MediaTek MT8678
- MediaTek MT8755
- MediaTek MT8775
- MediaTek MT8792
- MediaTek MT8793
- MediaTek MT8795T
- MediaTek MT8796
- MediaTek MT8798
- MediaTek MT8863
- MediaTek MT8873
- MediaTek MT8883
- MediaTek MT8893
Timeline
- 2026-07-01: advisory: Published in MediaTek July 2026 Product Security Bulletin