Executive brief
MediaTek's TFA (Trusted Firmware-A) component, which provides security services in mobile chipsets, contains a missing bounds check that allows out-of-bounds memory writes. An attacker with System-level privileges can exploit this to cause the device to crash or become unresponsive, disrupting service availability without requiring user interaction.
Technical details
This is an out-of-bounds write vulnerability (CWE-787) caused by insufficient bounds validation in the TFA component. The vulnerability can be triggered by a local actor who already possesses System privilege; no user interaction is required for exploitation. An attacker can write to memory outside allocated buffers, leading to local denial of service through device crashes or instability. A patch is available via Patch ID ALPS10991467.
Affected products
- MediaTek TFA
Timeline
- 2026-08-03: disclosed