Executive brief
MediaTek's HFRP (a component used in mobile chipsets) contains a missing bounds check that allows an attacker with System-level privileges to write data outside allocated memory. This vulnerability enables privilege escalation and could potentially allow an attacker to gain complete control of the device or cause it to malfunction.
Technical details
The vulnerability is an out-of-bounds write (CWE-787) in MediaTek's HFRP component, caused by a missing bounds check. An attacker who has already obtained System privilege can exploit this vulnerability without requiring user interaction to achieve local privilege escalation. The affected component likely resides in the firmware or bootloader code executed with elevated privileges. MediaTek has released patches (Patch ID: ALPS11049569) and this issue has not been observed in active exploitation as of the advisory publication date.
Affected products
- MediaTek HFRP
Timeline
- 2026-08-03: disclosed
- 2026-08-03: patched: Patch ID ALPS11049569 released