---
id: CVE-2026-20466
title: >-
  In sec boot, there is a possible escalation of privilege due to a heap buffer
  overflow
summary: >-
  In sec boot, there is a possible escalation of privilege due to a heap buffer
  overflow. This could lead to local escalation of privilege, if an attacker has
  physical access to the device, with no additional execution privileges needed.
  U…
severity: none
cwe:
  - CWE-787
published: '2026-08-03'
updated: '2026-08-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20466'
references:
  - url: 'https://www.mediatek.com/product-security-bulletin/August-2026'
    label: security@mediatek.com
tags:
  - nvd
ingestedAt: '2026-08-03T06:23:47.148Z'
epss: 0.00223
epssPercentile: 0.11489
---

## Overview

In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AUTO00845351 (Note: For MT2737) / ALPS11072643 (Note: For MT6880, MT6890, MT6990); Issue ID: MSV-6929.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
