Junglewise Threat Intelligence

CVE-2026-20479: MediaTek Modem out-of-bounds read due to missing bounds check

CVE-2026-20479 · Severity: high · CVSS 7.5 · Published 2026-08-03

Technologies: MediaTek Mt8797 Firmware, MediaTek MT8791, MediaTek Mt6880, MediaTek Mt8675, MediaTek Mt6885, MediaTek Mt6873 Firmware, MediaTek Mt8675 Firmware, MediaTek Mt6855 Firmware, MediaTek Mt6883, MediaTek Mt6875, MediaTek Mt8791t, MediaTek Mt6855, MediaTek Mt8771, MediaTek Mt6877 Firmware, MediaTek Mt8791t Firmware, MediaTek Mt6877, MediaTek Mt6833 Firmware, MediaTek Mt6853 Firmware, MediaTek Mt6889, MediaTek Mt8797, MediaTek Mt6853, MediaTek Mt8791 Firmware, MediaTek Mt2735 Firmware, MediaTek Mt8771 Firmware, MediaTek MT2735, MediaTek Mt6889 Firmware, MediaTek MT6891, MediaTek Mt6890 Firmware, MediaTek MT6833, MediaTek Mt6891 Firmware, MediaTek Mt6875 Firmware, MediaTek Mt6893 Firmware, MediaTek Mt6893, MediaTek Mt6883 Firmware, MediaTek MT6873, MediaTek Mt6885 Firmware, MediaTek Modem, MediaTek Mt6880 Firmware, MediaTek Mt6890. Vendors: MediaTek.

Executive brief

MediaTek's modem component, which handles cellular connectivity in smartphones and IoT devices, contains a flaw that allows remote attackers to trigger a denial-of-service condition. An attacker controlling a rogue cellular base station can exploit this vulnerability without requiring any special privileges or user interaction, potentially disrupting device connectivity and communications.

Technical details

This vulnerability is an out-of-bounds read in MediaTek's modem firmware caused by a missing bounds check. The flaw exists in modem processing logic that handles cellular base station communications. An attacker can exploit this by operating a rogue 5G or 4G base station and transmitting a specially crafted message to a victim device connected to the malicious station. The out-of-bounds read can cause a crash or undefined behavior in the modem, leading to denial of service. MediaTek has released patches via security bulletin (Patch ID: MOLY00741071) with fixes available to OEMs.

Affected products

  • MediaTek Modem

Timeline

  • 2026-08-03: disclosed
  • 2026-08-03: advisory: MediaTek Product Security Bulletin published

References

Related threats