
Beautiful heap overflow writeup on mediatek download agent. Chimera’s “secret sauce” was heapb8 - usb size mismatch letting you corrupt chunk headers for arbitrary write. works on dimensity 9400/8400, patched as CVE-2025-20656/20658. full chain in penumbra now #MediaTek #infosec
Post summary
A heap overflow in the Mediatek download agent allows arbitrary write; a full exploit chain exists in Penumbra, the vulnerability is patched under CVE‑2025‑20656/20658.
