Junglewise Threat Intelligence

CVE-2026-20464: MediaTek HEVC decoder out-of-bounds write via integer overflow

CVE-2026-20464 · Severity: medium · CVSS 6.5 · Published 2026-08-03

Technologies: MediaTek Mt6761, MediaTek Mt8766, MediaTek Mt8768. Vendors: MediaTek.

Executive brief

MediaTek chipsets include an HEVC (H.265) video decoder used to process video content. A flaw in this decoder allows an attacker with system-level privileges to write data outside allocated memory bounds, potentially leading to unauthorized privilege escalation or device compromise.

Technical details

The vulnerability is a CWE-787 out-of-bounds write caused by an integer overflow in the HEVC decoder subcomponent. An attacker who has already obtained system privilege can trigger this flaw without requiring user interaction. The integer overflow leads to incorrect buffer boundary calculations, allowing write operations beyond allocated memory regions. This can result in code execution or further privilege escalation. Patches are available via Patch ID ALPS11104718.

Affected products

  • MediaTek MT6761
  • MediaTek MT8766
  • MediaTek MT8768

Timeline

  • 2026-08-03: disclosed

References

Related threats