Autocrypt reportedly announced on September 29, 2026, that its Red Team had found two vulnerabilities while researching Little Kernel (LK), open-source embedded-kernel software used during the boot process of MediaTek system-on-chip (SoC) products. The team reported the findings separately to MediaTek and the LK project.

How the two CVEs were handled

A CVE is a standardized identifier for a specific vulnerability. The two findings received different reported handling:

CVE identifierReported handling
CVE-2026-20466MediaTek reportedly registered one vulnerability reported by Autocrypt under this identifier.
CVE-2026-50971An additional finding reportedly went through MediaTek’s bug bounty program and was incorporated into an official upstream LK patch.

What an upstream LK patch means

An upstream patch is a change to a project’s shared codebase. Device firmware is a separate software build for particular hardware, so an upstream code change and a device firmware release are distinct things.