Sceawere

Vulnerability Detail

CVE-2026-20528UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CCCI Out-of-Bounds Memory Access

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.7
Creation Date
17h ago
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Attack Type
CWE-787 Out-of-bounds Write
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In ccci, there is a possible out of bounds write and read due to a missing bounds check. This could lead to local information disclosure, memory corruption, crashes, or privilege escalation if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS11428950 (Note: For MT6880, MT6890) / ALPS10563453 (Note: For MT6980D, MT6990, MT6986, MT6986D, MT6813, MT6988) / AUTO00858766 (Note: For MT2735, MT2737); Issue ID: MSV-9893.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.7",
  "pubDate": "2026-10-05T02:16:51.520Z",
  "pubdate": "2026-10-05T02:16:51.520Z",
  "executiveSummary": "The CCCI (Core Communication Processor Interface) driver contains a critical vulnerability stemming from inadequate bounds checking during memory operations. This security flaw enables both out-of-bounds (OOB) read and write operations, posing significant risks to system integrity.\nThe vulnerability affects several MediaTek chipset platforms, specifically MT6880, MT6890, MT6980D, MT6990, MT6986, MT6986D, MT6813, MT6988, MT2735, and MT2737. Successful exploitation could lead to localized information disclosure, unauthorized memory corruption, system instability (crashes), or privilege escalation.\nExploitation requires that an attacker has already compromised the system to obtain System-level privileges. Furthermore, the attack vector necessitates user interaction to facilitate the exploitation sequence. The risk is primarily contained within the local environment, as the vulnerability resides within the low-level communication driver interfaces.",
  "technicalDetails": "The root cause of this vulnerability (identified as MSV-9893) is the absence of rigorous bounds verification within the CCCI driver logic. CCCI acts as the intermediary interface for communication between the application processor and the modem processor. When processing data structures or message buffers, the driver fails to validate the size or index of incoming data against the allocated buffer capacity.\nThe lack of sanitization allows for OOB read and write operations. An OOB write allows a malicious actor to overwrite adjacent memory addresses within the kernel heap or driver context. By carefully crafting the input payload, an attacker can corrupt critical data structures, function pointers, or control flow metadata. Conversely, an OOB read allows for the unauthorized retrieval of sensitive data residing in memory regions adjacent to the buffer, potentially leaking cryptographic keys, session tokens, or other restricted kernel-space information.\nThe exploitation flow begins with the attacker operating under already-acquired System privileges. Through the defined CCCI interface, the attacker provides a specifically malformed input that bypasses the omitted bounds check. Given the requirement for user interaction, the attacker must influence a user-initiated action that triggers the driver to process the malicious buffer. Upon execution, the vulnerable function performs an operation (read or write) on an address outside of the intended memory boundary.\nIf the exploit targets write operations, the corruption can lead to arbitrary code execution by overwriting return addresses or function pointers. If the target is an OOB read, the attacker can systematically extract sensitive memory contents by manipulating the index offsets. The ultimate impact is highly dependent on the system state at the time of the exploit, ranging from minor service disruption and kernel panics (denial of service) to full system compromise if the memory corruption is leveraged to elevate privileges beyond the System level to higher kernel-level execution contexts."
}
CVE-2026-20528: CCCI Out-of-Bounds Memory Access (MEDIUM Severity, CVSS: 6.7) | Sceawere