Impact
The vulnerability exists in the trusted_mem component of MediaTek chipsets and results from improper input validation. An attacker who has already acquired System privilege can exploit the flaw to elevate privileges further, potentially gaining full control over the device. This leads to a classic local privilege escalation scenario where the attacker moves from a lower privileged account to one with higher system-level authority.
Affected Systems
The affected products are MediaTek, Inc. chipsets as referenced in the Mediatek product security bulletin for August 2026. The specific firmware or chipset model is not disclosed, but any device running the vulnerable trusted_mem implementation is at risk. The patch ID AUTO00834868 addresses this issue.
Risk and Exploitability
The CVSS score is 6 and the EPSS score is <1%, indicating a low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog, indicating no known active exploits. User interaction is required for exploitation, which may limit the attack surface. Nevertheless, once an adversary achieves System privilege, the escalation offers significant risk to device integrity and confidentiality.
OpenCVE Enrichment