In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSV-3899.
Cite this page
CVE-2026-20446. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-20446
Use CWE-787, Mediatek vendor hub and Mt6813 Firmware product page to widen CVE-2026-20446 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-20433, CVE-2026-20432 and CVE-2026-20431 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 6th, 2026.