important · Mobile — MediaTek
A local caller can reach a heap overwrite in MediaTek’s video decoder.
Affects
MediaTek chipset video-decoder firmware and drivers used across Android mobile devices and other embedded products.
The vendor establishes a local out-of-bounds write but does not identify the calling API or precisely describe the caller’s starting privilege.
Detail and 4 sources
We do not know whether browser, messenger, or media-framework input can reach the decoder without an existing local foothold.
Chain to watch
Deliver malformed media through a browser, messenger, or Android media framework→↓Reach the affected MediaTek vdec path→↓Trigger the heap overwrite from a remote delivery path→↓Remote media reachability without prior local execution is not established.
Unverified chainTest malformed samples through major Android media routes on representative affected chipsets.
Sources
Researchhttps://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/20xxx/CVE-2026-20501.jsonResearchhttps://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/20xxx/CVE-2026-20502.jsonVendorMediaTek | Home PageSecondaryMediaTek September batch includes video-decoder heap writes with local privilege-escalation impact