Executive brief
MediaTek's DA (Display Architecture or similar component) contains a memory safety flaw that allows an attacker with physical access to trigger a denial-of-service condition by overwriting memory beyond intended bounds. While this requires device access, it can crash the affected component and disrupt device functionality without requiring elevated privileges or user interaction.
Technical details
The vulnerability is an out-of-bounds write (CWE-787) caused by a missing bounds check in the DA subcomponent. An attacker with physical access to the device can exploit this flaw locally to cause a denial-of-service condition. The attack requires no elevated privileges and no user interaction. MediaTek has issued patches via ALPS10991588 (for MT6880, MT6890, MT6990, MT6988, MT6986, MT6813) and AUTO00851171 (for MT2735, MT2737). The issue (MSV-7790) has been addressed in the August 2026 security bulletin and is not known to be exploited in the wild.
Affected products
- MediaTek MT6880 as of August 2026
- MediaTek MT6890 as of August 2026
- MediaTek MT6990 as of August 2026
- MediaTek MT6988 as of August 2026
- MediaTek MT6986 as of August 2026
- MediaTek MT6813 as of August 2026
- MediaTek MT2735 as of August 2026
- MediaTek MT2737 as of August 2026
Timeline
- 2026-08-03: disclosed: Published in MediaTek August 2026 Product Security Bulletin
- 2026-08-03: patched: Patches available via ALPS10991588 and AUTO00851171; notified to OEMs for at least two months prior