Junglewise Threat Intelligence

CVE-2026-20490: MediaTek CCCI out-of-bounds read

CVE-2026-20490 · Severity: medium · CVSS 4.4 · Published 2026-08-03

Technologies: MediaTek Mt6982vb, MediaTek MT6988, MediaTek Mt6813 Firmware, MediaTek MT6813, MediaTek Mt6986, MediaTek Mt6986 Firmware, MediaTek Mt6982vb Firmware, MediaTek Mt6988 Firmware. Vendors: MediaTek.

Executive brief

MediaTek's CCCI (Cross-Core Communication Interface) component, used in mobile chipsets and IoT devices, contains a memory access vulnerability that could cause the device to crash or become unresponsive. An attacker with system-level privileges could trigger this denial-of-service condition without needing user interaction, potentially disrupting critical device operations or services running on affected hardware.

Technical details

The vulnerability is an out-of-bounds read in the CCCI subcomponent caused by missing bounds checking. The attack vector is local with a precondition of requiring attacker possession of System (kernel) privilege level. When triggered, the out-of-bounds memory access can cause a local denial of service. The exact affected chipsets and product lines are not explicitly detailed in the provided reference, though the advisory indicates MediaTek smartphone, IoT, and networking products using the affected CCCI code path. MediaTek has issued Patch ID ALPS10981501 to address this issue (Issue ID MSV-7669).

Affected products

  • MediaTek CCCI Unspecified

Timeline

  • 2026-08-03: disclosed
  • 2026-08-03: advisory: MediaTek Product Security Bulletin August 2026

References

Related threats