MediaTek's October bulletin fixes 43 flaws, including two critical modem memory bugs
MediaTek's monthly security bulletin lists two critical out-of-bounds write flaws in modem firmware affecting more than 50 chipsets, alongside nine high-severity issues in video, AI and modem components.
At a glance
- MediaTek's October 2026 bulletin, published 5 October, lists 43 CVEs across its chipset portfolio.
- CVE-2026-20519 and CVE-2026-20520 are rated critical: out-of-bounds writes in the Modem component caused by a missing bounds check.
- Each critical entry affects more than 50 chipsets, from MT2716 up to flagship-class parts such as MT6991.
- MediaTek says it is not aware of active exploitation and that device makers were notified at least two months before publication.
MediaTek published its October 2026 Product Security Bulletin on 5 October, disclosing 43 vulnerabilities across its chipset portfolio. Two of them are rated critical, and both sit in the Modem component — the part of the platform that handles cellular communication and is therefore reachable without any action by the device owner. MediaTek chips power a very large share of mid-range and budget Android phones as well as tablets, televisions and IoT hardware, so the bulletin matters well beyond any single vendor's handsets.
What happened
According to the bulletin, the two critical entries are CVE-2026-20519 and CVE-2026-20520. MediaTek describes each identically: "There is a possible out of bounds write due to a missing bounds check." Both were found internally rather than reported by an outside researcher, and the bulletin records the same affected chipset list for both.
That list runs to more than 50 parts and spans several generations, from automotive and entry-level chips such as MT2716, MT2735 and MT2737 through widely deployed phone platforms including MT6833, MT6853, MT6877, MT6893 and MT6895, up to recent flagship-class silicon such as MT6989, MT6990, MT6991 and MT6993, plus the MT8xxx series used in tablets and smart displays. Alongside the two critical issues, MediaTek lists nine high-severity flaws affecting the video decoder (vdec), video encoder (venc), the Video HAL, the neuropilot AI stack, the apu accelerator and the Modem itself.
Technical details
An out-of-bounds write in baseband firmware is a serious class of bug because the modem processes data that arrives over the air and sits at a privilege boundary below the operating system. MediaTek's bulletin does not publish exploitation prerequisites, proof-of-concept detail or CVSS vectors for these entries, and no attack has been attributed to any actor. The company states plainly: "we are not aware of any active exploitation of these vulnerabilities in the wild."
The high-severity set is a mix of memory corruption and input validation problems. CVE-2026-20521 is described as a stack-based buffer overflow in the Video HAL, CVE-2026-20522 and CVE-2026-20523 as out-of-bounds writes in neuropilot, CVE-2026-20524 as improper input validation in apu, while CVE-2026-20525 and CVE-2026-20527 are listed as modem system crashes and CVE-2026-20526 as another modem out-of-bounds write.
Who is affected
End users cannot act on a MediaTek bulletin directly. The company says device OEMs "have been notified of all the issues and the corresponding security patches for at least two months before publication," which means the fixes should already be in handset makers' hands; whether they reach a given phone depends entirely on that vendor's update policy and on whether the model is still supported.
What to do
Install the latest security update offered for the device and check the Android security patch level in system settings. Fleet administrators should map which MediaTek platforms exist in their estate, compare them against the bulletin's chipset list, and press suppliers for a delivery date where no update has shipped. Devices that have reached end of support will not receive these fixes at all and should be planned out of service, particularly where they sit on networks that matter.
Related CVEs
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



