Junglewise Threat Intelligence

CVE-2026-20471: MediaTek DA out-of-bounds write

CVE-2026-20471 · Severity: medium · CVSS 4.6 · Published 2026-08-03

Technologies: MediaTek Mt6880, MediaTek MT6988, MediaTek MT6813, MediaTek Mt6986, MediaTek MT2735, MediaTek MT6990, MediaTek MT2737, MediaTek Mt6890. Vendors: MediaTek.

Executive brief

MediaTek's DA (Display Architecture or similar component) contains a memory safety flaw that allows an attacker with physical access to trigger a denial-of-service condition by overwriting memory beyond intended bounds. While this requires device access, it can crash the affected component and disrupt device functionality without requiring elevated privileges or user interaction.

Technical details

The vulnerability is an out-of-bounds write (CWE-787) caused by a missing bounds check in the DA subcomponent. An attacker with physical access to the device can exploit this flaw locally to cause a denial-of-service condition. The attack requires no elevated privileges and no user interaction. MediaTek has issued patches via ALPS10991588 (for MT6880, MT6890, MT6990, MT6988, MT6986, MT6813) and AUTO00851171 (for MT2735, MT2737). The issue (MSV-7790) has been addressed in the August 2026 security bulletin and is not known to be exploited in the wild.

Affected products

  • MediaTek MT6880 as of August 2026
  • MediaTek MT6890 as of August 2026
  • MediaTek MT6990 as of August 2026
  • MediaTek MT6988 as of August 2026
  • MediaTek MT6986 as of August 2026
  • MediaTek MT6813 as of August 2026
  • MediaTek MT2735 as of August 2026
  • MediaTek MT2737 as of August 2026

Timeline

  • 2026-08-03: disclosed: Published in MediaTek August 2026 Product Security Bulletin
  • 2026-08-03: patched: Patches available via ALPS10991588 and AUTO00851171; notified to OEMs for at least two months prior

References

Related threats