Executive brief
MediaTek's modem component, which handles cellular connectivity in smartphones and IoT devices, contains a flaw that allows remote attackers to trigger a denial-of-service condition. An attacker controlling a rogue cellular base station can exploit this vulnerability without requiring any special privileges or user interaction, potentially disrupting device connectivity and communications.
Technical details
This vulnerability is an out-of-bounds read in MediaTek's modem firmware caused by a missing bounds check. The flaw exists in modem processing logic that handles cellular base station communications. An attacker can exploit this by operating a rogue 5G or 4G base station and transmitting a specially crafted message to a victim device connected to the malicious station. The out-of-bounds read can cause a crash or undefined behavior in the modem, leading to denial of service. MediaTek has released patches via security bulletin (Patch ID: MOLY00741071) with fixes available to OEMs.
Affected products
- MediaTek Modem
Timeline
- 2026-08-03: disclosed
- 2026-08-03: advisory: MediaTek Product Security Bulletin published