ZeroHour

CVE-2026-20501

mass

Heap buffer overflow in MediaTek vdec firmware enables local privilege escalation

CVSS 3.1
8.4 high
EPSS
<1%p3
Published
()
Modified
AI analysis

CVE-2026-20501 is a heap-based buffer overflow (CWE-122) in the vdec (video decoder) component of firmware for a wide range of MediaTek chipsets, which can cause an out-of-bounds write when crafted data is processed by the decoder. A local attacker with no additional execution privileges — for example a low-privileged app or process on the device — could exploit it without any user interaction to gain elevated privileges. Affected devices are those running firmware for the listed MediaTek SoCs (MT2718, MT6580, MT6739, MT6761, MT6765, MT6768, MT6769, MT6779, MT6781, MT6785, MT6789 and MT6833), chips commonly found in budget Android smartphones, feature phones, smart TVs and other consumer/IoT hardware. There is no evidence of active exploitation: the flaw is not in CISA KEV, has an EPSS 30-day probability of about 0.1% (3rd percentile), and no public proof-of-concept is known. The fix ships via MediaTek/OEM firmware updates associated with Patch ID ALPS11262030 (Issue ID MSV-9197).

What to do: Apply the fixed firmware containing MediaTek patch ALPS11262030 (Issue MSV-9197) as soon as your device OEM or carrier ships it, and check your device's chipset against the affected list in vendor security bulletins. Because exploitation requires local code execution, the practical risk before patching is limited to attackers who can already run an app or process on the device, so avoid installing untrusted apps on affected devices. Organizations managing fleets of MediaTek-based phones, TVs or IoT hardware should prioritize OEM update rollouts for the listed SoCs.

Affected
MediaTek MT2718 firmware
MediaTek MT6580 firmware
MediaTek MT6739 firmware
MediaTek MT6761 firmware
MediaTek MT6765 firmware
MediaTek MT6768 firmware
MediaTek MT6769 firmware
MediaTek MT6779 firmware
MediaTek MT6781 firmware
MediaTek MT6785 firmware
MediaTek MT6789 firmware
MediaTek MT6833 firmware
Estimated exposure
massTens of millions of devices globally (order-of-magnitude estimate) — The listed MediaTek SoCs are entry-level and mid-range chipsets that have shipped in hundreds of millions of budget Android phones, feature phones and TV/IoT devices, so the population of devices potentially running vulnerable firmware is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197.

Vendors
mediatek
Products
mt2718 firmware, mt6580 firmware, mt6739 firmware, mt6761 firmware, mt6765 firmware, mt6768 firmware, mt6769 firmware, mt6779 firmware, mt6781 firmware, mt6785 firmware, mt6789 firmware, mt6833 firmware
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.