Executive brief
MediaTek's Audio Hardware Abstraction Layer (HAL) contains a use-after-free vulnerability that allows attackers with System privilege to escalate their access further. While the attacker must already have privileged access, this flaw could enable a malicious insider or another compromised system component to gain additional privileges without any user interaction required. This affects multiple MediaTek chipsets used in smartphones, IoT devices, and other products.
Technical details
A use-after-free vulnerability exists in the MediaTek Audio HAL that allows privilege escalation. The flaw involves memory being accessed after it has been freed, leading to potential code execution at a higher privilege level. Exploitation requires the attacker to already possess System privilege; no user interaction is needed. An attacker with System privilege can trigger the vulnerability to escalate their access. Patches have been provided to affected OEMs at least two months prior to public disclosure (Patch ID: ALPS11191981).
Affected products
- MediaTek Chipsets (Modem/Audio HAL) MT2716, MT6835, MT6858, MT6878, MT6881, MT6897, MT6899, MT6982VB, MT6986, MT6988, MT6991, MT6993, MT8668, MT8676, MT8678, MT8755, MT8775, MT8792, MT8793, MT8863, MT8873, MT8883 and others
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Patch ID ALPS11191981; OEMs notified at least 2 months prior