MediaTek Modem Uncaught Exception Leading to Remote Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the modem component of various MediaTek chipsets. This issue arises from an uncaught exception, which can cause a system crash. The vulnerability could be exploited remotely if a user equipment (UE) device is connected to a rogue base station controlled by an attacker. Notably, no special execution privileges are required for exploitation, and user interaction is not needed.

Impact

Exploitation of this vulnerability can cause the system to crash, leading to a denial-of-service condition where the device becomes unresponsive.

Remediation

MediaTek has issued a patch for this vulnerability, which can be applied by device manufacturers. Instructions for applying the patch can be obtained from MediaTek contacts.

Added: Feb 2, 2026, 9:33 AM
Updated: Feb 2, 2026, 9:33 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.7
exploitability
4.3
remediation
0.0
relevance
2.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.