Vulnerabilities · 7h ago

MediaTek Bulletin Pushes Risk to OEM Rollouts

MediaTek's October security bulletin lists 31 vulnerabilities across a wide set of its SoCs, including 2 critical flaws. INCIBE-CERT says MediaTek gave device makers the fixes at least two months before publication, so the bulletin is now a disclosure point rather than the start of remediation work.

The flaws can lead to memory corruption, privilege escalation, information disclosure, or crashes in affected devices, but the exposure is not resolved by MediaTek's advisory alone. For phones, routers, and other products built on these chips, safety depends on when the OEM or carrier turns that upstream fix into a firmware update, which means patch timing will vary by model and distribution channel.

What matters for readers is the rollout gap: the same MediaTek bulletin can leave one device line covered and another exposed for longer, even though both share the same upstream fix.

CVEs in this update

10 CVEs

Across MediaTek chipset.

0 critical · 8 high · 2 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-20586 · 8.8 HIGH

Highest EPSS: CVE-2026-20586 · 0.38%

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-10-06

Editions

Related stories