Executive brief
MediaTek chipsets include a display component that fails to validate memory access boundaries, allowing an attacker with system-level privileges to read sensitive information from device memory. This vulnerability requires the attacker to have already compromised the device at the highest privilege level, but once achieved, could expose confidential data including cryptographic keys, user credentials, or other protected information stored in memory.
Technical details
The vulnerability is a missing bounds check in the display subsystem of affected MediaTek chipsets, classified as CWE-125 (out-of-bounds read). An attacker with System privilege can trigger an out-of-bounds memory read by interacting with the display driver without requiring user interaction. The vulnerability allows reading adjacent memory regions that may contain sensitive information. The attack is local only and requires prior elevation to system privilege level. MediaTek issued patches (Patch ID: ALPS11004276) and notified device OEMs at least two months before the August 2026 public disclosure; no active exploitation in the wild has been reported.
Affected products
- MediaTek MT6761 <unknown>
- MediaTek MT8766 <unknown>
- MediaTek MT8768 <unknown>
Timeline
- 2026-08-03: disclosed: MediaTek Product Security Bulletin published
- 2026-08-03: patched: Patch ID ALPS11004276 available; OEMs notified minimum 2 months prior