CVE-2026-20433

8.8

MediaTek · MediaTek Chipset

A missing bounds check in the MediaTek modem firmware allows for an out of bounds write, potentially leading to remote privilege escalation when connected to a rogue base station.

Executive summary

A critical out of bounds write vulnerability in MediaTek chipsets could allow an attacker to achieve remote privilege escalation via a rogue base station connection.

Vulnerability

The flaw is an out of bounds write (CWE-787) occurring within the modem firmware. An unauthenticated attacker can trigger this vulnerability if a User Equipment device connects to a malicious base station under their control.

Business impact

The potential for remote privilege escalation poses a significant risk to device integrity and user privacy. Successful exploitation could grant an attacker full control over the mobile device, leading to complete compromise of sensitive data and system functionality. Given the CVSS score of 8.8, this vulnerability is classified as High severity, necessitating prompt remediation to prevent unauthorized system access.

Remediation

Immediate Action: Update the affected device firmware to the version containing the patch identified as MOLY01088681 by MediaTek.

Proactive Monitoring: Monitor device network logs for unusual base station handoff behavior or unexpected modem resets that may indicate exploitation attempts.

Compensating Controls: While direct mitigation is limited for mobile hardware, users should exercise caution when connecting to unknown or untrusted cellular networks in high-risk environments.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations and individual users relying on devices equipped with the specified MediaTek chipsets must prioritize the application of vendor-provided firmware updates. Due to the potential for remote escalation of privilege, failure to patch may leave devices vulnerable to sophisticated attackers operating rogue cellular infrastructure. Verify that all security patches are applied as soon as they are made available by the device manufacturer.

More MediaTek CVEs

Sources