FR
live
tag

#mediatek

MediaTek patches two critical modem flaws exploitable via a rogue base station

MediaTek’s October 2026 security bulletin closes 31 flaws, including two critical out-of-bounds writes in the modem (CVE-2026-20519 and CVE-2026-20520) that a rogue base station can trigger to escalate privileges with no user interaction. Treat the gap between MediaTek’s fix and its distribution by device makers as a risk in its own right, and audit the patch level of your Android fleet.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss