Executive brief
MediaTek modems are communication processors used in smartphones and IoT devices to handle cellular connectivity. A missing bounds check in the modem firmware can cause a system crash when a device connects to a rogue base station controlled by an attacker, resulting in service disruption. No special privileges or user interaction are required to exploit this vulnerability.
Technical details
This vulnerability is a denial-of-service flaw caused by improper bounds checking in the modem subcomponent, allowing an out-of-bounds memory access or crash condition. The attack is triggered over the network when a user equipment (UE) connects to a malicious base station controlled by the attacker. The attacker sends specially crafted input that bypasses validation, causing the modem to crash and temporarily disabling cellular connectivity. No authentication or elevated privileges are required, and the attack succeeds without any user interaction. A patch is available (MOLY00755024).
Affected products
- MediaTek Modem MT2716, MT6835, MT6858, MT6878, MT6881, MT6897, MT6899, MT6982VB, MT6986, MT6988, MT6991, MT6993, MT8668, MT8676, MT8678, MT8755, MT8775, MT8792, MT8793, MT8863, MT8873, MT8883
Timeline
- 2026-09-07: disclosed