CVE-2026-20519: High severity MediaTek Modem vulnerability
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778993; Issue ID: MSV-8898.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Modemto a version that resolves this vulnerability.Patch MOLY01778993
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Devices using the affected MediaTek Modem are exposed when a UE connects to a rogue base station controlled by an attacker. Exploitation does not require user interaction.
What access does an attacker need?
The attacker needs control of a rogue base station that the target UE connects to. No additional execution privileges are needed.
What is the potential impact?
The missing bounds check can cause an out-of-bounds write in the modem and may allow remote escalation of privilege.
What identifiers can be used to track the fix?
The vendor patch identifier is MOLY01778993, and the associated issue identifier is MSV-8898.