MediaTek October 2026 security bulletin (5 Oct): 31 chipset CVEs — two Critical modem out-of-bounds writes (CVE-2026-20519/20520) reachable from a rogue base station with no user interaction; fixes ship via phone and tablet OEM updates
MediaTek published its October 2026 Product Security Bulletin on 5 October 2026, covering 31 vulnerabilities in its smartphone, tablet, IoT and automotive chipsets: 2 Critical, 9 High and 20 Medium. The two Critical bugs, CVE-2026-20519 and CVE-2026-20520, are out-of-bounds writes in the modem firmware caused by missing bounds checks; the CVE records say a device that connects to a rogue base station controlled by an attacker could suffer remote escalation of privilege with no user interaction and no extra execution privileges. Both affect a long list of 4G/5G modem chipsets (including the MT68xx and MT69xx Dimensity families and MT87xx/MT88xx parts) and were found internally. The High-rated issues include more modem out-of-bounds writes (for example CVE-2026-20526, which needs user interaction), out-of-bounds writes in the video decoder and encoder (CVE-2026-20586, CVE-2026-20589), a stack overflow in the Video HAL (CVE-2026-20521), and flaws in the NeuroPilot and APU AI-accelerator components. MediaTek says device makers received the patches at least two months before publication and that it is not aware of active exploitation. End users get the fixes only through their phone or tablet maker's security update, which often lands with or after the matching Android monthly patch.
- Product
- MediaTek chipsets (modem, video decoder/encoder, Video HAL, NeuroPilot, APU) in Android phones, tablets, IoT and automotive devices
- Versions
- Critical: CVE-2026-20519, CVE-2026-20520 (modem). High: CVE-2026-20521 to CVE-2026-20527, CVE-2026-20586, CVE-2026-20589. Medium: CVE-2026-20528 to CVE-2026-20544, CVE-2026-20579, CVE-2026-20587, CVE-2026-20588. Affected chipset lists per CVE are in the MediaTek bulletin; fixed builds are delivered by each device OEM.
- CVSS
- Critical (MediaTek severity, CVSS 3.1; numeric score not stated in the bulletin)
- Exploited in Australia?
- unknown
- Patch to
- Install your device maker's October 2026 (or later) security update on MediaTek-based phones, tablets and rugged or IoT devices, and check your MDM for handsets stuck on older patch levels. Retire devices that no longer get vendor security updates, because modem fixes cannot be applied any other way.
Primary: MediaTek — Product Security Bulletin, October 2026 (published 5 Oct 2026) · Vendor: CVE-2026-20519 record — modem out-of-bounds write via rogue base station (Patch ID MOLY01778993) · CVE: CVE-2026-20519, CVE-2026-20520, CVE-2026-20526, CVE-2026-20586, CVE-2026-20589, CVE-2026-20521 · CVE-2026-20520 record — modem out-of-bounds write via rogue base station (Patch ID MOLY01778988)
