Impact
The vulnerability is a use‑after‑free flaw that can corrupt memory during display handling. If an attacker already holds system privileges on the device and exploits this flaw, they can elevate their privileges locally. User interaction is not required, making the exploit possible in unattended situations.
Affected Systems
The affected products are MediaTek chipsets supplied by MediaTek, Inc. No specific firmware or hardware version is listed in the data.
Risk and Exploitability
The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation. The CVSS score is 6, indicating a moderate severity. However, because the flaw requires an attacker to already have system privileges, the risk is confined to environments where such privilege is obtainable, such as compromised devices or during firmware update processes. The severity, based on the use‑after‑free weakness, remains high for privileged attackers, so prioritizing remediation is advisable.
OpenCVE Enrichment