CVE-2026-20589

LOWCVSS 6.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9606.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-05: 110-05
Referenced assets1 URL
By indicator
Full discourse1 post
  • Rıdvan Yağlı@ridvanyagli

    🔴 MediaTek tarafından çok sayıda güvenlik açığı yayınlandı. CVE-2026-20519 ve CVE-2026-20520 kritik seviyede olup modem bileşenlerinde OOB Write üzerinden uzaktan yetki yükseltmeye yol açabiliyor. CVE-2026-20521–20527, CVE-2026-20586 ve CVE-2026-20589 ise yüksek seviyeli bellek güvenlik açıkları içeriyor. https://www.mediatek.com/product-security-bulletin/october-2026

    00002193
    2.4K followersView on X

Explore more