MediaTek Modem Out-of-Bounds Write Vulnerability Allowing Privilege Escalation

Vulnerability

A high-severity out-of-bounds write vulnerability has been identified in the modem component of various MediaTek chipsets. This issue arises from a missing bounds check, which could potentially lead to remote privilege escalation. Exploitation of this vulnerability requires user interaction and the presence of a rogue base station controlled by the attacker.

Impact

Exploitation of this vulnerability could result in unauthorized privilege escalation on the affected device.

Remediation

MediaTek has issued a patch for this vulnerability, which can be applied by device OEMs. Instructions for applying the patch are available through MediaTek contacts.

Added: Apr 7, 2026, 4:20 AM
Updated: Apr 7, 2026, 4:20 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
7.5
exploitability
3.8
remediation
7.7
relevance
5.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.