Impact
The vulnerability is an out‑of‑bounds read in the display code caused by a missing bounds check. Attackers who already possess System privilege can read memory beyond the intended buffer, exposing local data. This flaw represents a local information‑disclosure weakness.
Affected Systems
Affected product families include MediaTek MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6897, MT6899, MT6983, MT6985, MT6989, MT6991, MT6993, MT8196, MT8678, MT8793, as well as Android operating systems 14.0, 15.0, and 16.0.
Risk and Exploitability
CVSS score is 4.4, indicating moderate severity, while the EPSS score is below 1 percent, showing a very low probability of exploitation. The flaw is not listed in CISA’s KEV catalog. The attack vector is local; user interaction is not required, but the attacker must already have System privilege to trigger the out‑of‑bounds read. Given the restricted access needed, the overall risk is moderate but exploitation is unlikely under normal circumstances.
OpenCVE Enrichment