Executive brief
A security vulnerability exists in the MediaTek audio component used in many mobile devices, which manages how the operating system communicates with audio hardware. An attacker with local access to a device could bypass security controls to trigger sensitive functions that should normally be restricted. This could potentially allow unauthorized changes to system settings or interference with audio operations.
Technical details
An improper access control vulnerability exists in the MediaTek Audio Hardware Abstraction Layer (HAL). The flaw allows a local attacker to bypass intended permission restrictions and execute privileged functions within the audio subsystem. According to the CVSS 4.0 vector provided by Samsung, the exploit has a high impact on the integrity and availability of the subsequent system (SC:H/SI:H/SA:H), though the initial confidentiality impact is negligible. The issue is addressed in the MediaTek SMR Jun-2026 Release 1 update.
Affected products
- MediaTek Audio HAL prior to SMR Jun-2026 Release 1
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory