CVE-2026-20502
HIGHCVSS 8.4Description
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.
Timeline
Published:September 7th, 2026 2:17 AM
Last modified:September 9th, 2026 2:55 AM
CVSS Scoring
CVSS v3: 8.4 (HIGH)
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
From NVD CPE configuration data
Vendors
mediatek
Products
mt2718_firmwaremt6580_firmwaremt6739_firmwaremt6761_firmwaremt6765_firmwaremt6768_firmwaremt6769_firmwaremt6779_firmwaremt6781_firmwaremt6785_firmwaremt6789_firmwaremt6833_firmwaremt6835_firmwaremt6853_firmwaremt6855_firmwaremt6858_firmwaremt6873_firmwaremt6877_firmwaremt6878_firmwaremt6879_firmware
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports
Source: NIST NVD · Data may lag official sources by up to one minute