Executive brief
MediaTek's Bluetooth driver, used in mobile and IoT devices, contains a missing permission check that allows a local user to escalate their privileges without requiring any user interaction. An attacker with basic user-level access could exploit this flaw to gain elevated system permissions, potentially compromising device security and enabling further attacks.
Technical details
The vulnerability is a missing permission check in the MediaTek Bluetooth driver, classified as an authorization bypass. An attacker with local user-level execution privileges can exploit this flaw without requiring user interaction or network access. By bypassing the permission check, an attacker achieves privilege escalation from user to a higher privilege level. The patch ID WCNCR00488300 has been provided, and MediaTek has notified device OEMs of the fix for at least two months before public disclosure.
Affected products
- MediaTek Bluetooth driver
Timeline
- 2026-08-03: disclosed
- 2026-08-03: advisory: MediaTek Product Security Bulletin August 2026