Junglewise Threat Intelligence

CVE-2026-20480: MediaTek Audio HAL heap buffer overflow

CVE-2026-20480 · Severity: medium · CVSS 5.5 · Published 2026-08-03

Technologies: MediaTek Mt6890, MediaTek Mt6990 Firmware, MediaTek Mt6880, MediaTek MT6988, MediaTek Mt2737 Firmware, MediaTek Mt2735 Firmware, MediaTek MT2735, MediaTek Mt6988 Firmware, MediaTek Mt6890 Firmware, MediaTek MT6990, MediaTek MT2737, MediaTek Mt6880 Firmware. Vendors: MediaTek.

Executive brief

MediaTek's Audio HAL (Hardware Abstraction Layer) is a critical audio processing component used in smartphones and IoT devices. A heap buffer overflow vulnerability allows a local attacker with user privileges to cause a denial of service or potentially execute code, impacting device stability and security.

Technical details

This vulnerability is a heap buffer overflow in the Audio HAL component, classified as CWE-787 (out-of-bounds write). The flaw allows local code execution with user privileges to write beyond heap buffer boundaries, leading to memory corruption. No user interaction is required for exploitation. The vulnerability affects multiple MediaTek chipsets including MT6880, MT6890, MT6980D, MT6988, MT6990, MT2735, and MT3737. Patches are available via Patch ID ALPS10960023 and AUTO00851189 depending on the chipset.

Affected products

  • MediaTek MT6880 <UNKNOWN>
  • MediaTek MT6890 <UNKNOWN>
  • MediaTek MT6980D <UNKNOWN>
  • MediaTek MT6988 <UNKNOWN>
  • MediaTek MT6990 <UNKNOWN>
  • MediaTek MT2735 <UNKNOWN>
  • MediaTek MT3737 <UNKNOWN>

Timeline

  • 2026-08-03: disclosed
  • 2026-08-03: patched: Patches available: ALPS10960023 (MT6880, MT6890, MT6980D, MT6988, MT6990) and AUTO00851189 (MT2735, MT3737)

References

Related threats