CVE-2026-20446 PUBLISHED

Assigner: MediaTek
Reserved: 03.11.2025 Published: 07.04.2026 Updated: 07.04.2026

In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSV-3899.

Product Status

Vendor MediaTek, Inc.
Product MediaTek chipset
Versions Default: unaffected
  • Version MT6813 is affected

References

Problem Types

  • CWE-787 Out-of-bounds Write CWE