MediaTek MediaTek

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any MediaTek product.

RSS Feeds for MediaTek security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in MediaTek products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by MediaTek Sorted by Most Security Vulnerabilities since 2018

MediaTek Mt698990 vulnerabilities

MediaTek Mt685550 vulnerabilities

MediaTek Mt689742 vulnerabilities

MediaTek Mt698540 vulnerabilities

MediaTek Mt687939 vulnerabilities

MediaTek Mt683538 vulnerabilities

MediaTek Mt698337 vulnerabilities

MediaTek Mt687837 vulnerabilities

MediaTek Mt689537 vulnerabilities

MediaTek Mt688637 vulnerabilities

MediaTek Mt819630 vulnerabilities

MediaTek Mt678128 vulnerabilities

MediaTek Mt867326 vulnerabilities

MediaTek Nr1626 vulnerabilities

MediaTek Mt678923 vulnerabilities

MediaTek Nr1722 vulnerabilities

MediaTek Nr1520 vulnerabilities

MediaTek Mt878119 vulnerabilities

MediaTek Iot Yocto16 vulnerabilities

MediaTek Lr12a9 vulnerabilities

MediaTek Lr138 vulnerabilities

MediaTek Mt83906 vulnerabilities

MediaTek Mt83705 vulnerabilities

MediaTek Nr17r4 vulnerabilities

MediaTek Nbiot Sdk4 vulnerabilities

MediaTek Mt99724 vulnerabilities

MediaTek Mt87981 vulnerability

MediaTek Mt79251 vulnerability

MediaTek Mt79271 vulnerability

MediaTek Mt8188t1 vulnerability

MediaTek Software Package1 vulnerability

MediaTek Mt83211 vulnerability

MediaTek Mt87861 vulnerability

MediaTek Mt83951 vulnerability

MediaTek Mt86671 vulnerability

MediaTek Mt87971 vulnerability

MediaTek Mt86761 vulnerability

MediaTek Mt8791t1 vulnerability

MediaTek Mt87891 vulnerability

MediaTek Mt86781 vulnerability

MediaTek Mt87651 vulnerability

MediaTek Mt87661 vulnerability

MediaTek Mt87881 vulnerability

MediaTek Mt87681 vulnerability

MediaTek Mt68531 vulnerability

MediaTek Lr111 vulnerability

MediaTek Lr151 vulnerability

MediaTek Mt27131 vulnerability

MediaTek Mt27181 vulnerability

MediaTek Mt67391 vulnerability

MediaTek Mt67531 vulnerability

MediaTek Mt67571 vulnerability

MediaTek Mt67611 vulnerability

MediaTek Mt67621 vulnerability

MediaTek Mt67631 vulnerability

MediaTek Mt67651 vulnerability

MediaTek Mt67681 vulnerability

MediaTek Mt67691 vulnerability

MediaTek Mt68331 vulnerability

MediaTek Mt79221 vulnerability

MediaTek Mt68731 vulnerability

MediaTek Mt68751 vulnerability

MediaTek Mt68771 vulnerability

MediaTek Mt68801 vulnerability

MediaTek Mt68811 vulnerability

MediaTek Mt68831 vulnerability

MediaTek Mt68851 vulnerability

MediaTek Mt68891 vulnerability

MediaTek Mt68901 vulnerability

MediaTek Mt68931 vulnerability

MediaTek Mt69901 vulnerability

MediaTek Mt79021 vulnerability

MediaTek Mt79201 vulnerability

MediaTek Mt79211 vulnerability

By the Year

In 2026 there have been 121 vulnerabilities in MediaTek with an average score of 6.5 out of ten. Last year, in 2025 MediaTek had 123 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in MediaTek in 2026 could surpass last years number. Last year, the average CVE base score was greater by 0.37




Year Vulnerabilities Average Score
2026 121 6.51
2025 123 6.88
2024 32 7.58
2023 18 6.78
2022 2 8.65

It may take a day or so for new MediaTek vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent MediaTek Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-20498 Aug 03, 2026
MediaTek Chipset: Privilege Escalation via geniezone Permission Bypass In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765.
CVE-2026-20495 Aug 03, 2026
Local Privilege Escalation: MediaTek Bluetooth Driver CVE-2026-20495 In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.
CVE-2026-20493 Aug 03, 2026
MediaTek WiFi Chipset OOB Write Enables Local DoS In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: BORA00154903; Issue ID: MSV-7575.
CVE-2026-20492 Aug 03, 2026
MediaTek Audio HAL race condition leads to local DoS In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735, MT2737); Issue ID: MSV-7583.
CVE-2026-20489 Aug 03, 2026
MediaTek Display Integer Overflow Enables Local Info Disclosure In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004274; Issue ID: MSV-7749.
CVE-2026-20488 Aug 03, 2026
MediaTek chipset bounds check bug CVE-2026-20488 In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757.
CVE-2026-20486 Aug 03, 2026
MediaTek chipset: imgsensor crash leads to privilege escalation In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833.
CVE-2026-20485 Aug 03, 2026
MediaTek MT6993 HFRP OOB Write Enables Priv Escalation In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931.
CVE-2026-20484 Aug 03, 2026
MediaTek TFA Info Disclosure via Missing Permission Check In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.
CVE-2026-20470 Aug 03, 2026
MediaTek Telephony Local Info Disclosure via Missing Permission Check In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11086431; Issue ID: MSV-8189.
CVE-2026-20483 Aug 03, 2026
MediaTek Telephony Escalation of Privilege via Missing Permission In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.
CVE-2026-20482 Aug 03, 2026
MediaTek WLAN STA DoS via excessive logging In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824.
CVE-2026-20481 Aug 03, 2026
OOB Write in MediaTek GenieZone Enables Local PrivEsc In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935.
CVE-2026-20497 Aug 03, 2026
OOB write in geniezone enables local privilege escalation on MediaTek In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.
CVE-2026-20480 Aug 03, 2026
MediaTek Audio HAL Heap Overflow Enables Local DoS In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D, MT6988, MT6990) / AUTO00851189 (Note: For MT2735, MT3737); Issue ID: MSV-7586.
CVE-2026-20479 Aug 03, 2026
MediaTek Modem OoB Read Remote DoS via Rogue Base Station In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00741071; Issue ID: MSV-7620.
CVE-2026-20478 Aug 03, 2026
MediaTek Audio HAL Heap Buffer Overflow, OOB Write, DoS (CVE-2026-20478) In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638.
CVE-2026-20477 Aug 03, 2026
MediaTek chipset out-of-bounds write leads to local privilege escalation In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11009963; Issue ID: MSV-7658.
CVE-2026-20476 Aug 03, 2026
Out-of-Bounds Read in MediaTek CCCI Leading to Local DoS In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660.
CVE-2026-20475 Aug 03, 2026
MediaTek Display OOB Write Enables Local Priv Escalation In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748.
CVE-2026-20474 Aug 03, 2026
Race Condition Enables Local Priv Escalation in MediaTek Chipset In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019183; Issue ID: MSV-7758.
CVE-2026-20473 Aug 03, 2026
MediaTek chipset Use-After-Free leading to local privilege escalation In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759.
CVE-2026-20472 Aug 03, 2026
MediaTek TFA OOB Write Local DoS (Sys Priv) In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10991467; Issue ID: MSV-7764.
CVE-2026-20471 Aug 03, 2026
MediaTek Chipset OOB Write Vulnerability (CVE-2026-20471) In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10991588 (Note: For MT6880, MT6890, MT6990, MT6988, MT6986, MT6813) / AUTO00851171 (Note: For MT2735, MT2737); Issue ID: MSV-7790.
CVE-2026-20469 Aug 03, 2026
MediaTek chipset trusted_mem PrivEsc via Input Validation In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: AUTO00834868; Issue ID: MSV-6533.
CVE-2026-20468 Aug 03, 2026
MediaTek chipset apusys local privilege escalation In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00833804; Issue ID: MSV-6741.
CVE-2026-20467 Aug 03, 2026
MediaTek Chipset Priv Escalation via Bounds Check In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767.
CVE-2026-20466 Aug 03, 2026
MediaTek MCU: MT2737/MT6880/MT6890/MT6990 SecureBoot Heap Overflow PrivEsc In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AUTO00845351 (Note: For MT2737) / ALPS11072643 (Note: For MT6880, MT6890, MT6990); Issue ID: MSV-6929.
CVE-2026-20465 Aug 03, 2026
MediaTek WLAN AP Driver OOB Write Escalation In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00489200; Issue ID: MSV-7834.
CVE-2026-20464 Aug 03, 2026
MediaTek HEVC Decoder OOB Write via Integer Overflow (CVE-2026-20464) In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11104718; Issue ID: MSV-8297.
CVE-2026-20463 Jul 01, 2026
MediaTek Modem Priv Escalation via Permission Bypass In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: MOLY01716533; Issue ID: MSV-6309.
CVE-2026-20462 Jul 01, 2026
MediaTek Telephony Heap Buffer Overflow (CVE-2026-20462) In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11006447; Issue ID: MSV-7871.
CVE-2026-20461 Jul 01, 2026
Modem OOB Write CVE-2026-20461 (MediaTek) In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01267281 / MOLY01318201; Issue ID: MSV-6486.
CVE-2026-20460 Jul 01, 2026
Modem Info Disclosure via Unvalidated Input in MediaTek Modems In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01811421; Issue ID: MSV-6788.
CVE-2026-20459 Jul 01, 2026
Remote DoS via Input Validation in MediaTek Modem In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01816800; Issue ID: MSV-6842.
CVE-2026-20458 Jul 01, 2026
Modem mem corruption missing bound check remote privilege escalation In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01402160; Issue ID: MSV-7298.
CVE-2026-20457 Jul 01, 2026
MediaTek Modem Input Validation Flaw Leading to Remote DoS In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01826924; Issue ID: MSV-7301.
CVE-2026-20456 Jun 01, 2026
Mediatek WLAN STA Driver: Bounds Overflow Crash for Local DoS In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480851; Issue ID: MSV-6338.
CVE-2026-20455 Jun 01, 2026
MediaTek Geniezone OOB Write Enabling Local Priv Escalation In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6784.
CVE-2026-20454 Jun 01, 2026
geniezone OOB Write Race Enables Local PrivEsc In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6786.
CVE-2026-20453 Jun 01, 2026
MediaTek geniezone OOB Write Local Escalation (CVE-2026-20453) In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791.
CVE-2026-20452 Jun 01, 2026
MediaTek WLAN AP Driver Heap Buffer Overflow Allows Remote Code Execution In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295.
CVE-2026-20451 May 04, 2026
MediaTek slbc OOB Write via Type Confusion Local Priv Escalation In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10828685; Issue ID: MSV-6504.
CVE-2026-20450 May 04, 2026
Remote Modem DoS via Crash in MediaTek Modems In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01753620; Issue ID: MSV-6100.
CVE-2026-20449 May 04, 2026
MediaTek Modem Heap Overflow Enables Remote DoS In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue ID: MSV-6148.
CVE-2026-20448 May 04, 2026
Privilege Escalation in GenieZone via Missing Permission Check In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513; Issue ID: MSV-6281.
CVE-2026-20447 May 04, 2026
GenieZone Local Priv Escalation via Missing Bounds Check In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10724073; Issue ID: MSV-6296.
CVE-2026-20446 Apr 07, 2026
Integer Overflow OOB Write in Mediatek Secure Boot In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSV-3899.
CVE-2026-20433 Apr 07, 2026
MediaTek Modem OOB Write (CVE-2026-20433) In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01088681; Issue ID: MSV-4460.
CVE-2026-20432 Apr 07, 2026
MediaTek Modem OOB Write Remote Priv Escalation via Rogue Base Station In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01406170; Issue ID: MSV-4461.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.