Junglewise Threat Intelligence

CVE-2026-20478: MediaTek Audio HAL heap buffer overflow

CVE-2026-20478 · Severity: medium · CVSS 5.5 · Published 2026-08-03

Technologies: MediaTek Mt6990 Firmware, MediaTek Mt6880, MediaTek MT6988, MediaTek Mt2737 Firmware, MediaTek Mt2735 Firmware, MediaTek MT2735, MediaTek Mt6988 Firmware, MediaTek Mt6890 Firmware, MediaTek MT6990, MediaTek MT2737, MediaTek Mt6880 Firmware, MediaTek Mt6890. Vendors: MediaTek.

Executive brief

MediaTek's Audio Hardware Abstraction Layer (HAL) contains a heap buffer overflow vulnerability that could allow a local attacker with user-level privileges to crash the audio service or potentially execute code. This affects various MediaTek chipsets used in smartphones and IoT devices. While exploitation requires local system access, no user interaction is needed once an attacker has that access.

Technical details

The vulnerability is a heap buffer overflow (CWE-787: Out-of-bounds Write) in the Audio HAL component affecting multiple MediaTek chipsets. The root cause is insufficient bounds checking that allows out-of-bounds memory writes. Exploitation requires local user-level execution privileges; network access is not required. An attacker with local access can trigger the vulnerability without user interaction to cause denial of service or potentially achieve code execution. MediaTek has released patches identified as ALPS10981454 (for MT6880, MT6890, MT6988, MT6990) and AUTO00851293 (for MT2735, MT2737).

Affected products

  • MediaTek MT6880 chipset
  • MediaTek MT6890 chipset
  • MediaTek MT6988 chipset
  • MediaTek MT6990 chipset
  • MediaTek MT2735 chipset
  • MediaTek MT2737 chipset

Timeline

  • 2026-08-03: disclosed: MediaTek Product Security Bulletin published

References

Related threats