MediaTek published its October 2026 Product Security Bulletin on October 5, listing 31 vulnerabilities affecting certain chipsets: two critical, nine high and 20 medium. The two critical issues affect the modem and are classified as out-of-bounds writes.

The two critical flaws affect the modem

The bulletin identifies CVE-2026-20519 and CVE-2026-20520 as critical modem vulnerabilities, both classified as CWE-787. An out-of-bounds write occurs when software writes data outside the memory space allocated for it. The bulletin assesses severity using CVSS v3.1.

Chipsets named in the bulletin

MediaTek lists chipsets associated with the critical pair, including MT6833, MT6853, MT6877, MT6885, MT6895, MT6983, MT6991, MT6993, MT8668, MT8792, MT8793 and MT8893. These are chipset identifiers, not retail phone model names. MediaTek says its affected-chipset lists may be incomplete.

MediaTek’s statements on patches and exploitation

MediaTek said affected device manufacturers had been notified and received corresponding patches at least two months before the bulletin’s publication. That advance notice applies to manufacturers; consumer-device update timing depends on manufacturers’ and carriers’ firmware-update processes.

MediaTek also said it was not aware of active exploitation in the wild when the bulletin was published. That statement describes the company’s awareness at that time.

What the bulletin means for device owners

The bulletin identifies affected chipsets. A chipset name alone does not identify a specific retail device, while consumer updates are handled through manufacturers’ and carriers’ update processes.