Home

Description

In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10607099; Issue ID: MSV-6118.

PUBLISHED Reserved 2025-11-03 | Published 2026-03-02 | Updated 2026-03-30 | Assigner MediaTek

Problem types

CWE-522 Insufficiently Protected Credentials

Product status

Default status
unaffected

MT2737
affected

MT6739
affected

MT6761
affected

MT6765
affected

MT6768
affected

MT6781
affected

MT6789
affected

MT6813
affected

MT6833
affected

MT6853
affected

MT6855
affected

MT6877
affected

MT6878
affected

MT6879
affected

MT6880
affected

MT6885
affected

MT6886
affected

MT6890
affected

MT6893
affected

MT6895
affected

MT6897
affected

MT6983
affected

MT6985
affected

MT6989
affected

MT6990
affected

MT6993
affected

MT8169
affected

MT8186
affected

MT8188
affected

MT8370
affected

MT8390
affected

MT8676
affected

MT8678
affected

MT8696
affected

MT8793
affected

References

corp.mediatek.com/product-security-bulletin/March-2026

cve.org (CVE-2026-20435)

nvd.nist.gov (CVE-2026-20435)

Download JSON