Executive brief
MediaTek's imgsensor component handles camera image processing on mobile chipsets. A flaw in its error handling can cause the application to crash unexpectedly. While the crash itself may seem benign, an attacker who already has System-level privileges could exploit this to escalate or maintain their access to the device.
Technical details
The vulnerability is a local privilege escalation flaw caused by incorrect error handling in the imgsensor subcomponent. The issue manifests as an application crash that can be triggered by a malicious actor who has already obtained System privilege on the device. No user interaction is required for exploitation. The vulnerability affects MediaTek chipsets and is addressed by patch ID ALPS11012302 (Issue ID MSV-7833). The attack vector is local, requiring an attacker to already have elevated system privileges.
Affected products
- MediaTek imgsensor <UNKNOWN>
Timeline
- 2026-08-03: disclosed
- 2026-08-03: patched: Patch ID ALPS11012302; Issue ID MSV-7833