CVE-2026-20438

In MAE, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431920; Issue ID: MSV-5835.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt2718:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6899:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6991:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8168:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8169:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8186:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8695:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8696:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8793:-:*:*:*:*:*:*:*

History

03 Mar 2026, 12:48

Type Values Removed Values Added
First Time Mediatek mt6991
Mediatek mt8793
Mediatek mt8696
Mediatek mt2718
Google android
Google
Mediatek mt6899
Mediatek mt8186
Mediatek mt8169
Mediatek mt8678
Mediatek mt8168
Mediatek mt8188
Mediatek mt8695
Mediatek
CPE cpe:2.3:h:mediatek:mt2718:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8696:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8793:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8168:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8186:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8169:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8695:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6899:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6991:-:*:*:*:*:*:*:*
References () https://corp.mediatek.com/product-security-bulletin/March-2026 - () https://corp.mediatek.com/product-security-bulletin/March-2026 - Vendor Advisory

02 Mar 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.4

02 Mar 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-02 09:16

Updated : 2026-03-03 12:48


NVD link : CVE-2026-20438

Mitre link : CVE-2026-20438

CVE.ORG link : CVE-2026-20438


JSON object : View

Products Affected

mediatek

  • mt2718
  • mt6991
  • mt8678
  • mt8696
  • mt8186
  • mt8188
  • mt8169
  • mt6899
  • mt8793
  • mt8695
  • mt8168

google

  • android
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition