CVE-2026-20539: MediaTek Modem vulnerability
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8913.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01774038
Event History
Frequently Asked Questions
Who is exposed to this issue?
Devices using the affected MediaTek Modem software may be exposed when a UE connects to an attacker-controlled rogue base station.
What does an attacker need to exploit it?
The attacker needs control of a rogue base station that the UE connects to. No additional execution privileges or user interaction are required.
What is the likely impact of exploitation?
Successful exploitation can cause a remote denial of service through an out-of-bounds read in the modem.
How can this issue be tracked for remediation?
Use Patch ID MOLY01774038 or Issue ID MSV-8913 when coordinating remediation with MediaTek or downstream device suppliers.