CVE-2026-20502
massOut-of-Bounds Write in MediaTek vdec Firmware Enables Local Privilege Escalation
CVE-2026-20502 is an out-of-bounds write (CWE-122, heap-based buffer overflow) in the vdec (video decoder) component of MediaTek chipset firmware, caused by a missing bounds check. It can be triggered locally when the vulnerable decoder processes crafted input, with no user interaction and no additional execution privileges required. A successful attacker gains local escalation of privilege, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.4). Affected devices are those running firmware for MediaTek SoCs including MT2718, MT6580, MT6739, MT6761, MT6765, MT6768, MT6769, MT6779, MT6781, MT6785, MT6789, and MT6833, with the fix shipped as MediaTek patch ALPS11262030 (issue MSV-9196) via OEM firmware updates. There is no public proof of concept, the issue is not in CISA KEV, and EPSS is low (0.1%, 2nd percentile), indicating exploitation has not been observed.
What to do: Obtain and install the MediaTek fix (patch ID ALPS11262030) through your device vendor's firmware or Android security update channel, and check with the OEM whether your specific device on the listed SoCs is scheduled to receive it. The flaw is local-only (AV:L), so exposure requires local code execution on an affected device and there is no network attack vector to mitigate in the meantime. With no public PoC, no KEV listing, and a low EPSS score, treat this as routine patch prioritization rather than urgent incident response.
| MediaTek MT2718 firmware | — |
| MediaTek MT6580 firmware | — |
| MediaTek MT6739 firmware | — |
| MediaTek MT6761 firmware | — |
| MediaTek MT6765 firmware | — |
| MediaTek MT6768 firmware | — |
| MediaTek MT6769 firmware | — |
| MediaTek MT6779 firmware | — |
| MediaTek MT6781 firmware | — |
| MediaTek MT6785 firmware | — |
| MediaTek MT6789 firmware | — |
| MediaTek MT6833 firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.
- Vendors
- mediatek
- Products
- mt2718 firmware, mt6580 firmware, mt6739 firmware, mt6761 firmware, mt6765 firmware, mt6768 firmware, mt6769 firmware, mt6779 firmware, mt6781 firmware, mt6785 firmware, mt6789 firmware, mt6833 firmware
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.