Description
In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AUTO00845351 (Note: For MT2737) / ALPS11072643 (Note: For MT6880, MT6890, MT6990); Issue ID: MSV-6929.
Published: 2026-08-03
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In the secure boot process of MediaTek chipsets, a heap buffer overflow vulnerability allows an attacker with physical access to raise privileges locally. The flaw resides in the handling of data during boot and does not require prior execution privileges or user interaction. Successful exploitation grants the attacker full control of the system, enabling the execution of arbitrary code and the potential compromise of all confidentiality, integrity, and availability guarantees of the device.

Affected Systems

The vulnerability affects MediaTek, Inc. chipsets, specifically MT2737, MT6880, MT6890, and MT6990. MediaTek has released patch packages identified as AUTO00845351 for MT2737 and ALPS11072643 for the other models. Devices running unsupported firmware versions remain at risk until the corresponding patch is applied.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity vulnerability. The EPSS score of < 1% shows that exploitation is currently unlikely. The vulnerability is not listed in CISA KEV. Because physical access is required, the attack surface is narrow but still significant for assets that can be accessed by adversaries. Attackers can trigger the overflow during boot, so securing the device physically and ensuring patch deployment are critical to mitigate the risk.

Generated by OpenCVE AI on August 4, 2026 at 10:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the MediaTek patch package AUTO00845351 for MT2737 or ALPS11072643 for MT6880, MT6890, and MT6990. The patch corrects the heap buffer overflow in secure boot, which is a CWE‑787 vulnerability.
  • If the patch is not immediately available, enforce strict physical security controls to prevent unauthorized access to the device and disable any non‑essential boot pathways that may expose the vulnerable firmware.
  • Continuously monitor firmware versions and apply future security updates from MediaTek to maintain protection against similar privileged‑escalation flaws.

Generated by OpenCVE AI on August 4, 2026 at 10:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Secure Boot Heap Buffer Overflow Enables Local Privilege Escalation

Mon, 03 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mediatek Chipset
Vendors & Products Mediatek
Mediatek mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AUTO00845351 (Note: For MT2737) / ALPS11072643 (Note: For MT6880, MT6890, MT6990); Issue ID: MSV-6929.
Weaknesses CWE-787
References

Subscriptions

Mediatek Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-08-03T19:38:19.691Z

Reserved: 2025-11-03T01:30:59.015Z

Link: CVE-2026-20466

cve-icon Vulnrichment

Updated: 2026-08-03T19:38:14.379Z

cve-icon NVD

Status : Received

Published: 2026-08-03T03:16:41.433

Modified: 2026-08-03T20:17:18.230

Link: CVE-2026-20466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:00:07Z

Weaknesses