Impact
The vulnerability is an out‑of‑bounds write caused by a missing bounds check in the MediaTek Decoding Algorithm, which could allow a local attacker with physical access to trigger a failure resulting in denial of service. No additional privileges or user interaction are required. This weakness falls under CWE‑787.
Affected Systems
Affected are MediaTek chipsets, including MT6880, MT6890, MT6990, MT6988, MT6986, MT6813, MT2735, and MT2737, as identified by the vendor's patch IDs. System administrators should check whether their devices use these components.
Risk and Exploitability
Because the flaw requires only physical presence to trigger, the risk remains significant for environments where attackers can touch the hardware. The EPSS score of < 1% indicates a very low probability of exploitation, and the CVSS score of 4.6 denotes a low‑severity vulnerability. The vulnerability is not listed in KEV, and the lack of a user interaction barrier suggests that the exploit can be performed with minimal effort by anyone who can gain access to the device.
OpenCVE Enrichment