Junglewise Threat Intelligence

CVE-2026-20466: MediaTek secure boot heap buffer overflow privilege escalation

CVE-2026-20466 · Severity: medium · CVSS 6.1 · Published 2026-08-03

Technologies: MediaTek Mt6880, MediaTek MT6990, MediaTek MT2737, MediaTek Mt6890. Vendors: MediaTek.

Executive brief

MediaTek's secure boot component, which protects the boot process on mobile devices and IoT products, contains a heap buffer overflow vulnerability. An attacker with physical access to a device can exploit this flaw to escalate privileges and gain unauthorized control over the system, potentially allowing them to modify firmware or compromise the entire device.

Technical details

The vulnerability is a heap buffer overflow in MediaTek's secure boot implementation (vulnerable component: sec boot). The attack vector is physical access to the device; no additional execution privileges or user interaction is required. An attacker can trigger the buffer overflow to overwrite heap memory, leading to local privilege escalation. Patches are available under Patch IDs AUTO00845351 (for MT2737) and ALPS11072643 (for MT6880, MT6890, MT6990). The vendor was notified at least two months prior to public disclosure, and no active exploitation in the wild has been reported as of the advisory date.

Affected products

  • MediaTek MT2737 Unspecified (Patch ID: AUTO00845351)
  • MediaTek MT6880 Unspecified (Patch ID: ALPS11072643)
  • MediaTek MT6890 Unspecified (Patch ID: ALPS11072643)
  • MediaTek MT6990 Unspecified (Patch ID: ALPS11072643)

Timeline

  • 2026-08-03: disclosed: MediaTek Product Security Bulletin published; CVE-2026-20466 assigned
  • 2026-06-03: other: Device OEMs notified at least two months prior to disclosure
  • patched: Patches available: AUTO00845351 (MT2737), ALPS11072643 (MT6880/MT6890/MT6990)

References

Related threats