Impact
In the secure boot process of MediaTek chipsets, a heap buffer overflow vulnerability allows an attacker with physical access to raise privileges locally. The flaw resides in the handling of data during boot and does not require prior execution privileges or user interaction. Successful exploitation grants the attacker full control of the system, enabling the execution of arbitrary code and the potential compromise of all confidentiality, integrity, and availability guarantees of the device.
Affected Systems
The vulnerability affects MediaTek, Inc. chipsets, specifically MT2737, MT6880, MT6890, and MT6990. MediaTek has released patch packages identified as AUTO00845351 for MT2737 and ALPS11072643 for the other models. Devices running unsupported firmware versions remain at risk until the corresponding patch is applied.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity vulnerability. The EPSS score of < 1% shows that exploitation is currently unlikely. The vulnerability is not listed in CISA KEV. Because physical access is required, the attack surface is narrow but still significant for assets that can be accessed by adversaries. Attackers can trigger the overflow during boot, so securing the device physically and ensuring patch deployment are critical to mitigate the risk.
OpenCVE Enrichment