Junglewise Threat Intelligence

CVE-2026-20491: MediaTek med out-of-bounds write due to incorrect bounds check

CVE-2026-20491 · Severity: medium · CVSS 5.5 · Published 2026-08-03

Technologies: MediaTek Mt6990 Firmware, MediaTek MT6988, MediaTek Mt2737 Firmware, MediaTek Mt2735 Firmware, MediaTek MT2735, MediaTek Mt6988 Firmware, MediaTek Mt6890 Firmware, MediaTek MT6990, MediaTek MT2737, MediaTek Mt6890. Vendors: MediaTek.

Executive brief

MediaTek's med component, used in smartphone chipsets and IoT devices, contains a vulnerability that allows an attacker with local access and user-level privileges to trigger an out-of-bounds memory write. This could cause system crashes and service denial, or potentially allow unauthorized code execution, affecting the stability and security of connected devices.

Technical details

The vulnerability is an out-of-bounds write in MediaTek's med component caused by an incorrect bounds check (CWE-787). Exploitation requires local access with user-level execution privileges; remote exploitation is not possible. The flaw affects multiple MediaTek chipsets including MT6890, MT6990, MT6988, MT2735, and MT2737. An attacker can trigger denial of service or potentially escalate privileges through memory corruption. MediaTek has issued patches with IDs ALPS10981478 and AUTO00851173 for affected chipsets.

Affected products

  • MediaTek med component

Timeline

  • 2026-08-03: disclosed
  • 2026-08-03: patched: Patches ALPS10981478 and AUTO00851173 released

References

Related threats