MEDIATEK’S October 2026 security bulletin patches 31 vulnerabilities across its smartphone, tablet and IoT chipsets. The spotlight is on two critical modem flaws, CVE-2026-20519 and CVE-2026-20520, which could allow remote privilege escalation via a rogue cellular base station. MediaTek states that, at present, there is no evidence of exploitation in the wild, and no public proof-of-concept has been confirmed.
The bulletin rates two flaws as Critical, nine as High and twenty as Medium, with the most serious impacts affecting more than 50 chipsets across MT2735/ MT2737 automotive and IoT modems, as well as MT6833/MT6853/MT6877/MT6893 smartphone chips and other MT69xx/MT87xx/MT88xx families. The two modem flaws (CVE-2026-20519 and CVE-2026-20520) involve out-of-bounds writes resulting from missing bounds checks and can enable remote privilege escalation if a device connects to a rogue base station.
What happened and who is affected: the October bulletin consolidates fixes for a broad set of MediaTek components, including critical modem flaws in multiple MT chip families and a separate vdec issue (CVE-2026-20586) that could allow remote escalation via crafted content. High-severity issues are spread across the NeuroPilot AI framework, the APU driver and the Video HAL, while many medium flaws involve system privileges within components like mtee, aidl, display and ccci.
The recommended response is to install the latest OEM firmware updates and Android security patches as soon as they are released by device manufacturers, since MediaTek states fixes reach users through OEM updates rather than a direct company patch. The full chipset list and CVE details are published in MediaTek’s October 2026 product security bulletin.