Junglewise Threat Intelligence

CVE-2026-20494: MediaTek WiFi out-of-bounds read

CVE-2026-20494 · Severity: medium · CVSS 5.5 · Published 2026-08-03

Technologies: MediaTek Mt6990 Firmware, MediaTek MT6988, MediaTek Mt6988 Firmware, MediaTek Mt6890 Firmware, MediaTek MT6990, MediaTek Mt6890. Vendors: MediaTek.

Executive brief

MediaTek's WiFi driver contains a missing bounds check that allows local information disclosure. An attacker with System-level privileges can read memory outside allocated buffers, potentially exposing sensitive data. No user interaction is required for exploitation.

Technical details

This vulnerability is a missing bounds check in the MediaTek WiFi subsystem that leads to an out-of-bounds read. The root cause stems from insufficient validation when processing WiFi-related operations, allowing an attacker to read memory beyond the intended buffer boundaries. Exploitation requires System privilege level access and no user interaction. An attacker can disclose sensitive information stored in adjacent memory regions. MediaTek has issued patches identified by Patch IDs ALPS10960006, BORA00155314, BORA00155001, and BORA00154907.

Affected products

  • MediaTek WiFi driver <UNKNOWN>

Timeline

  • 2026-08-03: disclosed

References

Related threats