PatchSiren

MediaTek, Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM MediaTek, Inc. CVE published 2026-08-03

CVE-2026-20489

PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T03:16:43.997Z and has not been modified since then. This vulnerability affects system administrators and security teams responsible for Mediatek-based systems, particularly those with System privilege access. An integer overflow in the display component could lead to local information disclosure if a malicio [truncated]

HIGH MediaTek, Inc. CVE published 2026-08-03

CVE-2026-20483

The CVE-2026-20483 record describes a potential escalation of privilege due to a missing permission check in Telephony. This vulnerability could lead to local escalation of privilege with no additional execution privileges needed, and user interaction is not required for exploitation. The affected product is Mediatek's Telephony system. The CVE record was published on 2026-08-03T03:16:43.430Z and has not [truncated]

MEDIUM MediaTek, Inc. CVE published 2026-08-03

CVE-2026-20475

A possible out of bounds write vulnerability exists in the display component of Mediatek-based systems due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. The vulnerability has a high impact on system integrity and could be exploited by attackers with System privileg [truncated]

MEDIUM MediaTek, Inc. CVE published 2026-08-03

CVE-2026-20471

A possible out of bounds write due to a missing bounds check was reported in DA. This could lead to local denial of service if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. The affected products are those using Mediatek chipsets, particularly those with physical access risks. Organizations should assess and p [truncated]

MEDIUM MediaTek, Inc. CVE published 2026-08-03

CVE-2026-20467

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T03:16:41.547Z and has not been modified since then. The CVE-2026-20467 vulnerability is caused by a missing bounds check in apusys, which could lead to local escalation of privilege. This requires the attacker to have already obtained the System privilege. User interaction is not needed for explo [truncated]

MEDIUM MediaTek, Inc. CVE published 2026-08-03

CVE-2026-20466

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T03:16:41.433Z and has not been modified since then. CVE-2026-20466 is related to a heap buffer overflow in sec boot, leading to a possible escalation of privilege. This vulnerability affects devices with Mediatek chipsets, especially those in secure boot environments. Users and administrators sho [truncated]

MEDIUM MediaTek, Inc. CVE published 2026-06-01

CVE-2026-20456

A missing bounds check in the MediaTek WLAN STA driver can cause a system crash, leading to local denial of service. The vulnerability requires User execution privileges but does not require user interaction for exploitation. The issue has been assigned CWE-787 (Out-of-bounds Write) and is addressed by Patch ID WCNCR00480851.

HIGH MediaTek, Inc. CVE published 2026-06-01

CVE-2026-20455

A missing bounds check in the geniezone component creates an out-of-bounds write condition. The vulnerability requires an attacker to already hold System privilege, limiting exposure to post-compromise scenarios. No user interaction is needed for exploitation. The issue has been addressed via patch ALPS10873936 (Issue ID: MSV-6784).

MEDIUM MediaTek, Inc. CVE published 2026-06-01

CVE-2026-20454

A race condition in the geniezone component creates a possible out-of-bounds write. Successful exploitation could allow a malicious actor with existing System privileges to escalate privileges further. No user interaction is required for exploitation. The vulnerability has been addressed with Patch ID ALPS10873936 (Issue ID: MSV-6786).

MEDIUM MediaTek, Inc. CVE published 2026-06-01

CVE-2026-20453

A missing bounds check in the geniezone component creates an out-of-bounds write condition that could enable local privilege escalation. The vulnerability requires the attacker to already hold System privileges, meaning it represents a privilege-escalation path rather than an initial compromise vector. No user interaction is needed for exploitation. The issue has been addressed with patch ID ALPS10886526.

HIGH MediaTek, Inc. CVE published 2026-06-01

CVE-2026-20452

A heap buffer overflow vulnerability in a WLAN Access Point (AP) driver may allow remote proximal/adjacent attackers to achieve code execution. The flaw requires User execution privileges but does not require user interaction for exploitation. The vulnerability was disclosed in MediaTek's June 2026 Product Security Bulletin with Patch ID WCNCR00480138 and Issue ID MSV-6295. The weakness is classified as C [truncated]

HIGH MediaTek, Inc. CVE published 2026-04-07

CVE-2026-20432

PatchSiren debrief on CVE-2026-20432 based on the supplied source corpus. The CVE record was published on 2026-04-07T04:17:12.413Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Mediatek firmware, specifically the Modem component, and allows for a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privi [truncated]

MEDIUM MediaTek, Inc. CVE published 2026-04-07

CVE-2026-20431

A logic error in the Modem component of Mediatek products could lead to a possible system crash and remote denial of service. This issue has been assigned a CVSS score of 6.5 and a severity of MEDIUM. The vulnerability requires no user interaction and can be exploited remotely if a UE has connected to a rogue base station controlled by the attacker. The affected products and their configurations need to b [truncated]