Out-of-bounds read in MediaTek products - CVE-2026-20447
Published: May 4, 2026
Vulnerability identifier: #VU129559
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-20447
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
MT6768
MT6789
MT6899
MT6989
MT6991
MT6993
MT8196
MT8367
MT8766
MT8768
MT8781
MT8786
MT8788E
MT8791T
MT8793
MT8910
MT6877
MT6768
MT6789
MT6899
MT6989
MT6991
MT6993
MT8196
MT8367
MT8766
MT8768
MT8781
MT8786
MT8788E
MT8791T
MT8793
MT8910
MT6877
Software vendor:
MediaTek
MediaTek
Description
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to out-of-bounds read in geniezone when handling crafted local input. A local user can trigger the vulnerable condition to escalate privileges.
Remediation
Install security update from vendor's website.