important · Mobile — Zero-click
A rogue cellular base station can write outside two MediaTek modem buffers and remotely escalate privilege without user interaction.
Affects
MediaTek cellular modems used across phones, tablets, automotive systems and other embedded devices built on the listed chipsets.
Crafted cellular input reaches one of two parsing paths with a missing bounds check, producing an out-of-bounds write in privileged modem firmware.
Detail and 6 sources
MediaTek has announced a fix, but we could not retrieve the bulletin body, so the complete chipset matrix and device-level delivery status remain unresolved.
Chain to watch
Attacker operates a rogue cellular base station within range of the target.→↓The powered-on UE attaches to the attacker-controlled station.→↓Crafted cellular input reaches one of two modem parsing paths with a missing bounds check.→↓The input causes an out-of-bounds write in privileged modem firmware.→↓The vendor-assigned CVE records state that the condition permits remote escalation of privilege.→↓The precise radio message, resulting modem privilege, exploitability and behavior on a factory-stock bootloader-locked handset are not public
Unverified chainObtain MediaTek patches MOLY01778993 and MOLY01778988 or reproduce both issues on a stock handset while recording the over-the-air message and resulting execution context
Sources
ResearchCVE-2026-20520 | Out of Bounds Write in ModemResearchhttps://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/20xxx/CVE-2026-20519.jsonResearchhttps://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/20xxx/CVE-2026-20520.jsonCode / PoCcvelistV5/cves/2026/20xxx/CVE-2026-20519.json at main · CVEProject/cvelistV5 · GitHubCode / PoCcvelistV5/cves/2026/20xxx/CVE-2026-20520.json at main · CVEProject/cvelistV5 · GitHubVendorMediaTek | Home Page