Executive brief
MediaTek chipsets include a display driver component that processes graphics rendering requests. A missing bounds check in this driver allows a privileged attacker to write data outside allocated memory, potentially corrupting the kernel and gaining full system control. This could affect millions of smartphones, tablets, and IoT devices powered by MediaTek processors.
Technical details
The vulnerability is a out-of-bounds write (CWE-787) in the display subsystem caused by missing bounds validation. The flaw requires an attacker to already hold System privilege, meaning this is a local privilege escalation or privilege-boundary bypass vulnerability. No user interaction is required for exploitation once System access is obtained. An attacker can corrupt kernel memory or other privileged processes, potentially achieving kernel-level code execution. A patch is available; MediaTek identified this as Issue MSV-7658 with Patch ID ALPS11009963.
Affected products
- MediaTek Dimensity 5G
Timeline
- 2026-08-03: disclosed
- 2026-08-03: advisory: MediaTek Product Security Bulletin August 2026