Executive brief
MediaTek chipsets include a display component with a missing bounds check that allows an attacker with System privilege to trigger an out-of-bounds write. An attacker who has already compromised system-level access could exploit this flaw to escalate privileges further, potentially gaining complete control of the device. No user interaction is required once system-level access is obtained.
Technical details
This is an out-of-bounds write vulnerability (CWE-787) in the display subsystem of affected MediaTek chipsets, caused by a missing bounds check. The vulnerability requires the attacker to have already obtained System privilege level access; it is a local privilege escalation vector for an unprivileged-to-privileged boundary crossing. Exploitation does not require user interaction. The flaw affects display processing logic and can lead to memory corruption, enabling further privilege escalation. MediaTek has issued security patch ALPS11004276 (Issue ID MSV-7748) to address this issue.
Affected products
- MediaTek MT6761 Chipset Unspecified
Timeline
- 2026-08-03: disclosed
- other: Patch ID ALPS11004276 issued; OEMs notified 2+ months prior to publication