
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20437 is a use-after-free vulnerability in MediaTek's MAE (likely Media Abstraction Engine) component that can cause a system crash, resulting in local denial of service. It affects devices running Android 15.0 on specific MediaTek chipsets: MT2718, MT6899, MT6991, MT8678, and MT8793. The vulnerability was published on March 2, 2026, with a patch made available in MediaTek's March 2026 Product Security Bulletin. It carries a CVSS v3.1 base score of 4.4 (Medium) (MediaTek Bulletin, Red Hat CVE).
The root cause is a use-after-free condition (CWE-416) in the MAE component, where memory is accessed after it has been freed, leading to a potential system crash. Exploitation requires the attacker to have already obtained System-level privileges on the device, making this a local attack vector with high privilege requirements. No user interaction is needed once System privileges are acquired. The patch is identified as ALPS10431940 (Issue ID: MSV-5843) (MediaTek Bulletin).
Successful exploitation leads to a local denial of service via system crash, affecting availability with no impact on confidentiality or integrity. Because the attack requires pre-existing System privileges, the blast radius is limited — an attacker cannot use this vulnerability alone to escalate privileges or exfiltrate data. The affected chipsets (MT2718, MT6899, MT6991, MT8678, MT8793) span a range of MediaTek-powered Android 15.0 devices (MediaTek Bulletin).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.018% (0.000180), reflecting a very low probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (MediaTek Bulletin, Red Hat CVE).
MediaTek has released a patch (ALPS10431940) as part of the March 2026 Product Security Bulletin. Device manufacturers (OEMs) should integrate and distribute this patch to affected devices running Android 15.0 on MT2718, MT6899, MT6991, MT8678, or MT8793 chipsets. As a precautionary measure, restrict System-level privilege access to only trusted, verified applications. Users should apply OEM-provided security updates promptly (MediaTek Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."