Junglewise Threat Intelligence

CVE-2026-20493: MediaTek Wi-Fi out-of-bounds write

CVE-2026-20493 · Severity: medium · CVSS 4.4 · Published 2026-08-03

Technologies: MediaTek Mt6990 Firmware, MediaTek MT6988, MediaTek Mt6988 Firmware, MediaTek Mt6890 Firmware, MediaTek MT6990, MediaTek Mt6890. Vendors: MediaTek.

Executive brief

MediaTek Wi-Fi chipsets contain a memory safety vulnerability that allows a local attacker with system privileges to crash the device or potentially cause data corruption. This affects many smartphones, tablets, and IoT devices that rely on MediaTek's wireless components. An attacker who has already gained system-level access could exploit this to disable network functionality or destabilize the device.

Technical details

This is an out-of-bounds write vulnerability in the Wi-Fi subsystem caused by missing bounds checking (CWE-787). The vulnerability requires local access and system privilege level, meaning an attacker must have already compromised the device or be an unprivileged process that can escalate privileges. No user interaction is needed once these preconditions are met. Exploitation can lead to local denial of service through memory corruption. MediaTek has issued patches (Patch ID: BORA00154903) and the vulnerability is tracked under Issue ID MSV-7575. There is currently no evidence of active exploitation in the wild.

Affected products

  • MediaTek Wi-Fi <UNKNOWN>

Timeline

  • 2026-08-03: disclosed
  • 2026-08-03: advisory: MediaTek security bulletin published; patches available for at least 2 months prior

References

Related threats