ZeroHour

CVE-2026-20502

mass

Out-of-Bounds Write in MediaTek vdec Firmware Enables Local Privilege Escalation

CVSS 3.1
8.4 high
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2026-20502 is an out-of-bounds write (CWE-122, heap-based buffer overflow) in the vdec (video decoder) component of MediaTek chipset firmware, caused by a missing bounds check. It can be triggered locally when the vulnerable decoder processes crafted input, with no user interaction and no additional execution privileges required. A successful attacker gains local escalation of privilege, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.4). Affected devices are those running firmware for MediaTek SoCs including MT2718, MT6580, MT6739, MT6761, MT6765, MT6768, MT6769, MT6779, MT6781, MT6785, MT6789, and MT6833, with the fix shipped as MediaTek patch ALPS11262030 (issue MSV-9196) via OEM firmware updates. There is no public proof of concept, the issue is not in CISA KEV, and EPSS is low (0.1%, 2nd percentile), indicating exploitation has not been observed.

What to do: Obtain and install the MediaTek fix (patch ID ALPS11262030) through your device vendor's firmware or Android security update channel, and check with the OEM whether your specific device on the listed SoCs is scheduled to receive it. The flaw is local-only (AV:L), so exposure requires local code execution on an affected device and there is no network attack vector to mitigate in the meantime. With no public PoC, no KEV listing, and a low EPSS score, treat this as routine patch prioritization rather than urgent incident response.

Affected
MediaTek MT2718 firmware
MediaTek MT6580 firmware
MediaTek MT6739 firmware
MediaTek MT6761 firmware
MediaTek MT6765 firmware
MediaTek MT6768 firmware
MediaTek MT6769 firmware
MediaTek MT6779 firmware
MediaTek MT6781 firmware
MediaTek MT6785 firmware
MediaTek MT6789 firmware
MediaTek MT6833 firmware
Estimated exposure
masslikely tens of millions of devices worldwide (order-of-magnitude estimate) — The affected SoC list spans MediaTek's heavily deployed budget/mid-range families (Helio A/P/G series and Dimensity 700-class MT6833) used across Android smartphones, TV boxes, and IoT devices, so the installed base running these firmware…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.

Vendors
mediatek
Products
mt2718 firmware, mt6580 firmware, mt6739 firmware, mt6761 firmware, mt6765 firmware, mt6768 firmware, mt6769 firmware, mt6779 firmware, mt6781 firmware, mt6785 firmware, mt6789 firmware, mt6833 firmware
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.