Executive brief
A use-after-free vulnerability exists in MediaTek's GPU processing component, which handles graphics rendering on mobile and IoT devices. An attacker with local access and user-level privileges could trigger a system crash and potentially disclose sensitive information from memory, but user interaction is required for successful exploitation.
Technical details
The vulnerability is a use-after-free flaw in the GPU driver component affecting multiple MediaTek chipsets. The root cause involves memory management where freed GPU memory objects are accessed after deallocation, potentially leading to system crashes and local information disclosure. Exploitation requires local access with user-level execution privileges and user interaction. An attacker can trigger the flaw to crash the system or leak sensitive data from freed memory regions. MediaTek has released security patches (Patch ID: ALPS11122991) and notified device OEMs at least two months prior to public disclosure; patches should be available through device manufacturers.
Affected products
- MediaTek MT6835 Unspecified
- MediaTek MT6858 Unspecified
- MediaTek MT6878 Unspecified
- MediaTek MT6881 Unspecified
- MediaTek MT6897 Unspecified
- MediaTek MT6899 Unspecified
- MediaTek MT6982VB Unspecified
- MediaTek MT6986 Unspecified
- MediaTek MT6988 Unspecified
- MediaTek MT6991 Unspecified
- MediaTek MT6993 Unspecified
- MediaTek MT8668 Unspecified
- MediaTek MT8676 Unspecified
- MediaTek MT8678 Unspecified
- MediaTek MT8755 Unspecified
- MediaTek MT8775 Unspecified
- MediaTek MT8792 Unspecified
- MediaTek MT8793 Unspecified
- MediaTek MT8863 Unspecified
- MediaTek MT8873 Unspecified
- MediaTek MT8883 Unspecified
Timeline
- 2026-09-07: disclosed: Publicly disclosed via MediaTek Product Security Bulletin
- 2026-07-07: patched: Patch available at least two months before disclosure (Patch ID: ALPS11122991)