Executive brief
A vulnerability exists in the modem component of several MediaTek chipsets used in mobile devices. If a device connects to a malicious cellular base station controlled by an attacker, the attacker could gain unauthorized control or elevated privileges on the device. This attack occurs over the air and does not require any interaction from the user.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the MediaTek Modem firmware due to a missing bounds check. The vulnerability is triggered when a User Equipment (UE) connects to a rogue base station controlled by an attacker. This memory corruption can lead to remote escalation of privilege (EoP) within the modem subsystem. No additional execution privileges or user interaction are required for exploitation. MediaTek has released a patch under Patch ID MOLY01402160 to address this issue.
Affected products
- MediaTek, Inc. MediaTek chipset MT2716, MT2737, MT6739, MT6761, MT6762, MT6763, MT6765, MT6767, MT6768, MT6769, MT6771, MT6779, MT6781, MT6783, MT6785, MT6789, MT6813, MT6835, MT6858, MT6878, MT6879, MT6881, MT6886, MT6895, MT6896, MT6897, MT6899, MT6980, MT6982, MT6983, MT6985, MT6986, MT6986D, MT6988, MT6989, MT6990, MT6991, MT6993, MT8666, MT8667, MT8668, MT8673, MT8676, MT8678, MT8755, MT8765, MT8766, MT8766R
Timeline
- 2026-07-01: advisory: Published by MediaTek and NVD