Junglewise Threat Intelligence

CVE-2026-20488: MediaTek display information disclosure via missing bounds check

CVE-2026-20488 · Severity: medium · CVSS 4.4 · Published 2026-08-03

Technologies: MediaTek Mt8786 Firmware, MediaTek MT8676, MediaTek Mt6993 Firmware, MediaTek Mt8367, MediaTek Mt8791t, MediaTek Mt8910 Firmware, MediaTek Mt6991, MediaTek Mt8188 Firmware, MediaTek MT6993, MediaTek Mt8367 Firmware, MediaTek Mt8676 Firmware, MediaTek Mt8791t Firmware, MediaTek Mt6761, MediaTek Mt8799 Firmware, MediaTek Mt8126 Firmware, MediaTek Mt8766, MediaTek Mt8189 Firmware, MediaTek Mt8766 Firmware, MediaTek Mt8668, MediaTek Mt8126, MediaTek Mt8171, MediaTek Mt6991 Firmware, MediaTek Mt8910, MediaTek Mt8188, MediaTek Mt8171 Firmware, MediaTek Mt8781, MediaTek Mt8678 Firmware, MediaTek Mt8668 Firmware, MediaTek Mt8781 Firmware, MediaTek MT8678, MediaTek Mt8189, MediaTek Mt8768 Firmware, MediaTek Mt8786, MediaTek Mt8799, MediaTek Mt8768. Vendors: MediaTek.

Executive brief

MediaTek chipsets include a display component that fails to validate memory access boundaries, allowing an attacker with system-level privileges to read sensitive information from device memory. This vulnerability requires the attacker to have already compromised the device at the highest privilege level, but once achieved, could expose confidential data including cryptographic keys, user credentials, or other protected information stored in memory.

Technical details

The vulnerability is a missing bounds check in the display subsystem of affected MediaTek chipsets, classified as CWE-125 (out-of-bounds read). An attacker with System privilege can trigger an out-of-bounds memory read by interacting with the display driver without requiring user interaction. The vulnerability allows reading adjacent memory regions that may contain sensitive information. The attack is local only and requires prior elevation to system privilege level. MediaTek issued patches (Patch ID: ALPS11004276) and notified device OEMs at least two months before the August 2026 public disclosure; no active exploitation in the wild has been reported.

Affected products

  • MediaTek MT6761 <unknown>
  • MediaTek MT8766 <unknown>
  • MediaTek MT8768 <unknown>

Timeline

  • 2026-08-03: disclosed: MediaTek Product Security Bulletin published
  • 2026-08-03: patched: Patch ID ALPS11004276 available; OEMs notified minimum 2 months prior

References

Related threats