Sceawere
Vulnerability Detail
CVE-2026-20528UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CCCI Out-of-Bounds Memory Access
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.7
- Creation Date
- 17h ago
- Vendor
- MediaTek, Inc.
- Product
- MediaTek chipset
- Attack Type
- CWE-787 Out-of-bounds Write
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In ccci, there is a possible out of bounds write and read due to a missing bounds check. This could lead to local information disclosure, memory corruption, crashes, or privilege escalation if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS11428950 (Note: For MT6880, MT6890) / ALPS10563453 (Note: For MT6980D, MT6990, MT6986, MT6986D, MT6813, MT6988) / AUTO00858766 (Note: For MT2735, MT2737); Issue ID: MSV-9893.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.7",
"pubDate": "2026-10-05T02:16:51.520Z",
"pubdate": "2026-10-05T02:16:51.520Z",
"executiveSummary": "The CCCI (Core Communication Processor Interface) driver contains a critical vulnerability stemming from inadequate bounds checking during memory operations. This security flaw enables both out-of-bounds (OOB) read and write operations, posing significant risks to system integrity.\nThe vulnerability affects several MediaTek chipset platforms, specifically MT6880, MT6890, MT6980D, MT6990, MT6986, MT6986D, MT6813, MT6988, MT2735, and MT2737. Successful exploitation could lead to localized information disclosure, unauthorized memory corruption, system instability (crashes), or privilege escalation.\nExploitation requires that an attacker has already compromised the system to obtain System-level privileges. Furthermore, the attack vector necessitates user interaction to facilitate the exploitation sequence. The risk is primarily contained within the local environment, as the vulnerability resides within the low-level communication driver interfaces.",
"technicalDetails": "The root cause of this vulnerability (identified as MSV-9893) is the absence of rigorous bounds verification within the CCCI driver logic. CCCI acts as the intermediary interface for communication between the application processor and the modem processor. When processing data structures or message buffers, the driver fails to validate the size or index of incoming data against the allocated buffer capacity.\nThe lack of sanitization allows for OOB read and write operations. An OOB write allows a malicious actor to overwrite adjacent memory addresses within the kernel heap or driver context. By carefully crafting the input payload, an attacker can corrupt critical data structures, function pointers, or control flow metadata. Conversely, an OOB read allows for the unauthorized retrieval of sensitive data residing in memory regions adjacent to the buffer, potentially leaking cryptographic keys, session tokens, or other restricted kernel-space information.\nThe exploitation flow begins with the attacker operating under already-acquired System privileges. Through the defined CCCI interface, the attacker provides a specifically malformed input that bypasses the omitted bounds check. Given the requirement for user interaction, the attacker must influence a user-initiated action that triggers the driver to process the malicious buffer. Upon execution, the vulnerable function performs an operation (read or write) on an address outside of the intended memory boundary.\nIf the exploit targets write operations, the corruption can lead to arbitrary code execution by overwriting return addresses or function pointers. If the target is an OOB read, the attacker can systematically extract sensitive memory contents by manipulating the index offsets. The ultimate impact is highly dependent on the system state at the time of the exploit, ranging from minor service disruption and kernel panics (denial of service) to full system compromise if the memory corruption is leveraged to elevate privileges beyond the System level to higher kernel-level execution contexts."
}