Cyber Security News

MediaTek Fixes 31 Security Flaws Affecting Modem, Video and AI Components

MediaTek has released its October 2026 Product Security Bulletin, which addresses 31 vulnerabilities across modem, video, AI processing, display, trusted execution, and system components used in a wide range of its chipsets.

The fixes include two critical modem out-of-bounds write vulnerabilities and nine high-severity flaws that could potentially lead to memory corruption, privilege escalation, or device crashes.

Published on October 5, the bulletin states that MediaTek notified affected device manufacturers and provided corresponding fixes at least two months before public disclosure.

The company also mentioned that it was not aware of any active exploitation of the reported vulnerabilities at the time of publication.

MediaTek Fixes 31 Security Flaws

The two critical vulnerabilities, tracked as CVE-2026-20519 and CVE-2026-20520, affect MediaTek modem components. Both issues arise from missing bounds checks, which can lead to out-of-bounds write conditions, classified under CWE-787.

Such flaws can allow improperly handled data to overwrite memory outside its intended boundaries, potentially compromising device stability or security.

The affected platforms include MT6833, MT6855, MT6877, MT6881, MT6893, MT6983, MT6991, MT6993, MT8668, MT8792, MT8793, and MT8893, among other MediaTek chipsets.

Memory corruption vulnerabilities in cellular baseband components are particularly concerning because modems manage mobile network communications and operate within a sensitive hardware and software environment on smartphones and connected devices.

MediaTek also addressed high-severity issues in its video processing stack. CVE-2026-20586 impacts the video decoder (vdec) component and could cause an out-of-bounds write.

Meanwhile, CVE-2026-20589 affects the video encoder (venc) component and involves a type-confusion weakness. These components are commonly used for processing multimedia content on smartphones, tablets, Chromebooks, and other MediaTek-powered devices.

The security bulletin further details flaws affecting MediaTek’s AI processing infrastructure. CVE-2026-20522 and CVE-2026-20523 impact the NeuroPilot framework and may trigger out-of-bounds writes.

Additionally, CVE-2026-20524 affects the application processing unit (APU) and may lead to memory corruption due to improper input validation.

Three medium-severity flaws, CVE-2026-20531, CVE-2026-20532, and CVE-2026-20542, are related to APU and APUSYS components. These vulnerabilities involve memory safety conditions, including use-after-free and double-free issues.

The disclosures highlight the increasing security importance of on-device AI software stacks as neural processing capabilities become more integrated into consumer hardware.

CVE Details

SeverityCVE countAffected areas
Critical2Modem
High9Video decoder/encoder, Video HAL, NeuroPilot, APU, modem
Medium20Video decoder, MTEE, META, CCCI, battery, display, AIDL, APU/APUSYS, modem
CVESeverityComponentPrimary impact
CVE-2026-20519CriticalModemOut-of-bounds write
CVE-2026-20520CriticalModemOut-of-bounds write
CVE-2026-20586HighvdecOut-of-bounds write
CVE-2026-20589HighvencType confusion/out-of-bounds write
CVE-2026-20521HighVideo HALPrivilege escalation
CVE-2026-20522 / 20523HighNeuroPilotOut-of-bounds write
CVE-2026-20524HighAPUMemory corruption
CVE-2026-20525HighModemSystem crash
CVE-2026-20526HighModemOut-of-bounds write
CVE-2026-20527HighModemSystem crash

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago