Executive brief
MediaTek's ccci is a component used in cellular modems across smartphones and IoT devices. A missing bounds check allows an attacker with local access to read memory outside of allocated buffers, potentially causing system crashes or information disclosure.
Technical details
The vulnerability is an out-of-bounds read in the ccci (Cellular Control Communication Interface) component resulting from a missing bounds check. The vulnerability requires local user execution privileges, but does not require user interaction for exploitation. An attacker can trigger the out-of-bounds read to cause denial of service through system crashes or potentially leak sensitive memory contents. MediaTek has issued a security patch with ID ALPS10981532 and this is tracked as Issue ID MSV-7660.
Affected products
- MediaTek ccci <UNKNOWN>
Timeline
- 2026-08-03: disclosed
- 2026-08-03: patched: Patch ID: ALPS10981532