CVE-2026-20466: CWE-787 Out-of-bounds Write in MediaTek, Inc. MediaTek chipset
CVE-2026-20466 is a medium severity vulnerability in MediaTek chipsets MT2737, MT6880, MT6890, and MT6990. It involves a heap buffer overflow in the secure boot process that could allow local escalation of privilege without user interaction. Exploitation requires physical access to the device but no additional execution privileges. The vulnerability is identified as CWE-787 (Out-of-bounds Write).
AI Analysis
Technical Summary
This vulnerability is a heap buffer overflow in the secure boot component of certain MediaTek chipsets (MT2737, MT6880, MT6890, MT6990). It allows an attacker with physical access to the device to escalate privileges locally without needing prior execution privileges or user interaction. The issue is tracked under Patch IDs AUTO00845351 (MT2737) and ALPS11072643 (MT6880, MT6890, MT6990) and Issue ID MSV-6929. The CVSS v3.1 score is 6.1, reflecting medium severity with high confidentiality and integrity impact but no availability impact.
Potential Impact
Successful exploitation could lead to local privilege escalation on affected devices, potentially allowing an attacker with physical access to gain higher privileges than intended. Confidentiality and integrity of the device could be compromised. No remote exploitation or user interaction is required, but physical access is mandatory.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Patch IDs are referenced but no explicit patch availability or official fix status is provided. Until a patch is confirmed, restrict physical access to affected devices to mitigate risk.
CVE-2026-20466: CWE-787 Out-of-bounds Write in MediaTek, Inc. MediaTek chipset
Description
CVE-2026-20466 is a medium severity vulnerability in MediaTek chipsets MT2737, MT6880, MT6890, and MT6990. It involves a heap buffer overflow in the secure boot process that could allow local escalation of privilege without user interaction. Exploitation requires physical access to the device but no additional execution privileges. The vulnerability is identified as CWE-787 (Out-of-bounds Write).
CVSS v3.1
Score 6.1medium
Affected software
MediaTek, Inc.
MediaTek chipset
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability is a heap buffer overflow in the secure boot component of certain MediaTek chipsets (MT2737, MT6880, MT6890, MT6990). It allows an attacker with physical access to the device to escalate privileges locally without needing prior execution privileges or user interaction. The issue is tracked under Patch IDs AUTO00845351 (MT2737) and ALPS11072643 (MT6880, MT6890, MT6990) and Issue ID MSV-6929. The CVSS v3.1 score is 6.1, reflecting medium severity with high confidentiality and integrity impact but no availability impact.
Potential Impact
Successful exploitation could lead to local privilege escalation on affected devices, potentially allowing an attacker with physical access to gain higher privileges than intended. Confidentiality and integrity of the device could be compromised. No remote exploitation or user interaction is required, but physical access is mandatory.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Patch IDs are referenced but no explicit patch availability or official fix status is provided. Until a patch is confirmed, restrict physical access to affected devices to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- MediaTek
- Date Reserved
- 2025-11-03T01:30:59.015Z
- State
- PUBLISHED
Threat ID: 6a700181bf32cb7a34d5c9e2
Added to database: 08/03/2026, 02:48:33 UTC
Last enriched: 08/10/2026, 14:56:56 UTC
Last updated: 09/12/2026, 22:01:32 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.