CVE-2026-20432

8.0

MediaTek · MediaTek chipset

A missing bounds check in MediaTek chipsets allows for an out-of-bounds write, potentially enabling remote privilege escalation when connected to a rogue base station.

Executive summary

A critical out-of-bounds write vulnerability in MediaTek chipsets could allow a remote attacker to escalate privileges if a user connects to a malicious base station.

Vulnerability

The flaw is an out-of-bounds write (CWE-787) occurring within the modem firmware. An unauthenticated attacker can trigger this condition by luring a target device to connect to a rogue base station, requiring user interaction to complete the malicious sequence.

Business impact

The potential for remote privilege escalation poses a significant threat to mobile device integrity and data confidentiality. With a CVSS score of 8.0, this high-severity vulnerability highlights the risk of unauthorized system control, which could lead to complete compromise of the affected device and access to sensitive user information.

Remediation

Immediate Action: Update the affected device firmware to the version containing Patch ID MOLY01406170 as provided by the device manufacturer or MediaTek.

Proactive Monitoring: Monitor device connectivity logs for unexpected base station handovers or unusual signal strength fluctuations which may indicate interaction with an unauthorized cell site.

Compensating Controls: Users should exercise caution when connecting to unknown or untrusted cellular networks and maintain updated device software to ensure security patches are applied.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

Given the high-severity nature of this privilege escalation flaw, organizations and individual users should prioritize the installation of security updates provided by their device vendors. Failure to apply the necessary firmware patches leaves devices vulnerable to compromise via malicious radio-based attacks.

More MediaTek CVEs

Sources