TL;DR
The October 2026 MediaTek security bulletin patches 31 vulnerabilities across its smartphone, tablet and IoT chipsets. Two critical modem flaws, CVE-2026-20519 and CVE-2026-20520, let a rogue cellular base station trigger remote privilege escalation. MediaTek says it is not aware of any exploitation in the wild.
- Total: 31 CVEs
- Severity: 9 High · 22 Medium
- Actively exploited: None confirmed
- Highest severity: 8.8 (High · CVSSv3) — CVE-2026-20586
- Action: Apply the latest security updates now
Too many Google alerts in your inbox? Switch to one weekly digest, sorted by severity.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-20586 | 8.8 | CWE-787 | Not exploited |
| CVE-2026-20521 | 8.4 | CWE-121 | Not exploited |
| CVE-2026-20522 | 8.4 | CWE-787 | Not exploited |
| CVE-2026-20523 | 8.4 | CWE-787 | Not exploited |
| CVE-2026-20524 | 8.4 | CWE-1285 | Not exploited |
| CVE-2026-20531 | 8.4 | CWE-416 | Not exploited |
| CVE-2026-20519 | 7.5 | CWE-787 | Not exploited |
| CVE-2026-20520 | 7.5 | CWE-787 | Not exploited |
Why It Matters
MediaTek chips run inside many Android phones, tablets and connected devices. This month’s MediaTek security bulletin rates 2 flaws Critical, 9 High and 20 Medium. The two critical bugs alone affect more than 50 chipsets, from smartphone chips to MT27xx automotive and IoT modems.
Crucially, MediaTek states, “At this time, we are not aware of any active exploitation of these vulnerabilities in the wild.” No public proof-of-concept has been confirmed either.
How the Attacks Work
Critical Modem Flaws
Each critical MediaTek modem vulnerability, CVE-2026-20519 and CVE-2026-20520, is an out-of-bounds write caused by a missing bounds check. The attack needs a victim device to connect to a rogue base station that the attacker controls. From there, the flaw could allow remote escalation of privilege. Moreover, the victim does not need to do anything.
High-Severity Bugs
CVE-2026-20526 is a similar MediaTek modem vulnerability, but it needs user interaction. Next, CVE-2026-20586 is an out-of-bounds write in the video decoder (vdec). It can also lead to remote privilege escalation if a user interacts with crafted content. Two more modem bugs, CVE-2026-20525 and CVE-2026-20527, let a rogue base station crash the device.
Meanwhile, the remaining high-severity flaws sit in the NeuroPilot AI framework, the APU driver and the Video HAL. Each could give a local attacker higher privileges.
Medium-Severity Bugs
Most of the 20 medium flaws require an attacker who already holds System privileges. They touch components such as mtee, aidl, display, battery and ccci. Several further modem bugs allow remote denial of service through a rogue base station.
Affected Versions
The critical modem flaws affect a long list of chipsets, including:
- MT2735 and MT2737 automotive and IoT modems
- MT6833, MT6853, MT6877 and MT6893 smartphone chips
- MT6983, MT6985, MT6989, MT6991 and MT6993 flagship chips
- MT87xx and MT88xx tablet and Chromebook chips
The vdec flaw CVE-2026-20586 hits a separate set, such as MT6768, MT6789, MT8186 and MT8195. Readers should check the full chipset list for each CVE in MediaTek’s bulletin.
Patch and Mitigation Steps
MediaTek notified device makers of all issues “for at least two months before publication.” However, fixes reach users only through OEM firmware updates. Install the latest Android security update from your phone maker as soon as it arrives.
Full chipset tables appear in the MediaTek October 2026 product security bulletin. Every OEM ships these fixes on its own schedule, so the MediaTek security bulletin date is only the starting point.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!