Executive brief
MediaTek's Telephony component, which handles phone call functionality in devices powered by MediaTek chipsets, contains a missing permission check that allows unauthorized access to sensitive phone-related information. A local attacker can exploit this vulnerability without additional privileges or user interaction to disclose private telephony data, potentially exposing call logs, contact information, or other sensitive communication details.
Technical details
This vulnerability is a missing permission check in MediaTek's Telephony subcomponent, resulting in improper access control (CWE-284 / related to authorization failures). The vulnerable code fails to validate that a caller possesses the necessary permissions before granting access to telephony information. The attack vector is local, requiring code execution on the device but no elevated privileges. An attacker with local code execution can directly query telephony APIs or data structures to retrieve protected information without proper authorization checks. Patches are available as indicated by Patch ID ALPS11086431.
Affected products
- MediaTek Telephony
Timeline
- 2026-08-03: disclosed
- 2026-08-03: patched: Patch ID ALPS11086431 available