MediaTek has released its October 2026 Product Security Bulletin, which addresses 31 vulnerabilities across modem, video, AI processing, display, trusted execution, and system components used in a wide range of its chipsets.
The fixes include two critical modem out-of-bounds write vulnerabilities and nine high-severity flaws that could potentially lead to memory corruption, privilege escalation, or device crashes.
Published on October 5, the bulletin states that MediaTek notified affected device manufacturers and provided corresponding fixes at least two months before public disclosure.
The company also mentioned that it was not aware of any active exploitation of the reported vulnerabilities at the time of publication.
The two critical vulnerabilities, tracked as CVE-2026-20519 and CVE-2026-20520, affect MediaTek modem components. Both issues arise from missing bounds checks, which can lead to out-of-bounds write conditions, classified under CWE-787.
Such flaws can allow improperly handled data to overwrite memory outside its intended boundaries, potentially compromising device stability or security.
The affected platforms include MT6833, MT6855, MT6877, MT6881, MT6893, MT6983, MT6991, MT6993, MT8668, MT8792, MT8793, and MT8893, among other MediaTek chipsets.
Memory corruption vulnerabilities in cellular baseband components are particularly concerning because modems manage mobile network communications and operate within a sensitive hardware and software environment on smartphones and connected devices.
MediaTek also addressed high-severity issues in its video processing stack. CVE-2026-20586 impacts the video decoder (vdec) component and could cause an out-of-bounds write.
Meanwhile, CVE-2026-20589 affects the video encoder (venc) component and involves a type-confusion weakness. These components are commonly used for processing multimedia content on smartphones, tablets, Chromebooks, and other MediaTek-powered devices.
The security bulletin further details flaws affecting MediaTek’s AI processing infrastructure. CVE-2026-20522 and CVE-2026-20523 impact the NeuroPilot framework and may trigger out-of-bounds writes.
Additionally, CVE-2026-20524 affects the application processing unit (APU) and may lead to memory corruption due to improper input validation.
Three medium-severity flaws, CVE-2026-20531, CVE-2026-20532, and CVE-2026-20542, are related to APU and APUSYS components. These vulnerabilities involve memory safety conditions, including use-after-free and double-free issues.
The disclosures highlight the increasing security importance of on-device AI software stacks as neural processing capabilities become more integrated into consumer hardware.
CVE Details
| Severity | CVE count | Affected areas |
|---|---|---|
| Critical | 2 | Modem |
| High | 9 | Video decoder/encoder, Video HAL, NeuroPilot, APU, modem |
| Medium | 20 | Video decoder, MTEE, META, CCCI, battery, display, AIDL, APU/APUSYS, modem |
| CVE | Severity | Component | Primary impact |
|---|---|---|---|
| CVE-2026-20519 | Critical | Modem | Out-of-bounds write |
| CVE-2026-20520 | Critical | Modem | Out-of-bounds write |
| CVE-2026-20586 | High | vdec | Out-of-bounds write |
| CVE-2026-20589 | High | venc | Type confusion/out-of-bounds write |
| CVE-2026-20521 | High | Video HAL | Privilege escalation |
| CVE-2026-20522 / 20523 | High | NeuroPilot | Out-of-bounds write |
| CVE-2026-20524 | High | APU | Memory corruption |
| CVE-2026-20525 | High | Modem | System crash |
| CVE-2026-20526 | High | Modem | Out-of-bounds write |
| CVE-2026-20527 | High | Modem | System crash |
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…