CVE-2026-20427 PUBLISHED

Assigner: MediaTek
Reserved: 03.11.2025 Published: 02.03.2026 Updated: 02.03.2026

In display, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5537.

Product Status

Vendor MediaTek, Inc.
Product MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6897, MT6899, MT6983, MT6985, MT6989, MT6991, MT6993, MT8196, MT8678, MT8793
Versions
  • Version Android 14.0, 15.0, 16.0 is affected

References

Problem Types

  • CWE-787 Out-of-bounds Write CWE