Executive brief
A security vulnerability exists in the Telephony component of several MediaTek chipsets used in mobile devices. If an attacker already has significant control over a device, they could exploit this flaw to gain even higher levels of system access. This could allow for deeper persistence on the device or unauthorized access to sensitive functions, though it requires the attacker to have already breached the device's initial security layers.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Telephony component of various MediaTek chipsets. The vulnerability allows for memory corruption which can be leveraged for local escalation of privilege. A precondition for exploitation is that the attacker must have already obtained System-level privileges on the device. No user interaction is required for successful exploitation. MediaTek has released a patch under ID ALPS11006447 to address this issue.
Affected products
- MediaTek MT6739
- MediaTek MT6761
- MediaTek MT6765
- MediaTek MT6768
- MediaTek MT6781
- MediaTek MT6789
- MediaTek MT6833
- MediaTek MT6853
- MediaTek MT6855
- MediaTek MT6877
- MediaTek MT6883
- MediaTek MT6885
- MediaTek MT6889
- MediaTek MT6893
- MediaTek MT8695
- MediaTek MT8696
- MediaTek MT8765
- MediaTek MT8766
- MediaTek MT8766R
- MediaTek MT8768
- MediaTek MT8781
- MediaTek MT8791
Timeline
- 2026-07-01: advisory
- 2026-07-01: disclosed