Junglewise Threat Intelligence

CVE-2026-20477: MediaTek display out-of-bounds write

CVE-2026-20477 · Severity: medium · CVSS 6 · Published 2026-08-03

Technologies: MediaTek MT8676, MediaTek Mt8188 Firmware, MediaTek Mt6993 Firmware, MediaTek Mt8910 Firmware, MediaTek Mt6991, MediaTek MT6993, MediaTek Mt8676 Firmware, MediaTek Mt8668, MediaTek Mt8799, MediaTek Mt8188, MediaTek Mt8189, MediaTek Mt6991 Firmware, MediaTek Mt8910, MediaTek Mt8781, MediaTek Mt8189 Firmware, MediaTek Mt8678 Firmware, MediaTek Mt8668 Firmware, MediaTek Mt8781 Firmware, MediaTek Mt8799 Firmware, MediaTek MT8678. Vendors: MediaTek.

Executive brief

MediaTek chipsets include a display driver component that processes graphics rendering requests. A missing bounds check in this driver allows a privileged attacker to write data outside allocated memory, potentially corrupting the kernel and gaining full system control. This could affect millions of smartphones, tablets, and IoT devices powered by MediaTek processors.

Technical details

The vulnerability is a out-of-bounds write (CWE-787) in the display subsystem caused by missing bounds validation. The flaw requires an attacker to already hold System privilege, meaning this is a local privilege escalation or privilege-boundary bypass vulnerability. No user interaction is required for exploitation once System access is obtained. An attacker can corrupt kernel memory or other privileged processes, potentially achieving kernel-level code execution. A patch is available; MediaTek identified this as Issue MSV-7658 with Patch ID ALPS11009963.

Affected products

  • MediaTek Dimensity 5G

Timeline

  • 2026-08-03: disclosed
  • 2026-08-03: advisory: MediaTek Product Security Bulletin August 2026

References

Related threats