---
id: CVE-2026-20528
title: >-
  In ccci, there is a possible out of bounds write and read due to a missing
  bounds check
summary: >-
  In ccci, there is a possible out of bounds write and read due to a missing
  bounds check. This could lead to local information disclosure, memory
  corruption, crashes, or privilege escalation if a malicious actor has already
  obtained the S…
severity: none
cwe:
  - CWE-787
vendor: 'MediaTek, Inc.'
product: MediaTek chipset
affected:
  - mediatek_chipset MT2735
  - mediatek_chipset MT2737
  - mediatek_chipset MT6813
  - mediatek_chipset MT6880
  - mediatek_chipset MT6890
  - mediatek_chipset MT6980D
  - mediatek_chipset MT6986
  - mediatek_chipset MT6986D
  - mediatek_chipset MT6988
  - mediatek_chipset MT6990
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T02:16:51.520'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20528'
references:
  - url: 'https://www.mediatek.com/product-security-bulletin/October-2026'
    label: security@mediatek.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T02:10:36.190Z'
---

## Overview

In ccci, there is a possible out of bounds write and read due to a missing bounds check. This could lead to local information disclosure, memory corruption, crashes, or privilege escalation if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS11428950 (Note: For MT6880, MT6890) / ALPS10563453 (Note: For MT6980D, MT6990, MT6986, MT6986D, MT6813, MT6988) / AUTO00858766 (Note: For MT2735, MT2737); Issue ID: MSV-9893.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
