Impact
A missing bounds check in the ccci component of MediaTek chipsets allows a local user to trigger an out‑of‑bounds read, causing a crash or corruption of the process that the user is running. This flaw is a classic example of CWE‑787, where an unchecked array or pointer accesses memory beyond its intended bounds. While it does not grant code execution or elevate privileges, the resulting denial of service can disrupt the stability of the victim device.
Affected Systems
All devices that incorporate MediaTek chipsets with the vulnerable ccci component are affected. The vulnerability description does not specify firmware or operating system versions, so any current or future releases lacking the ALPS10981532 patch should be treated as at risk until remediation is applied.
Risk and Exploitability
Exploitation requires local user privileges and does not need additional user interaction beyond the fact that the attacker uses a legitimate application or process. The EPSS score of below 1% indicates a low probability of widespread exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 5.5 places it in the moderate severity range, underscoring that while the threat is limited in scope, it can still impact user experience and system availability if left unpatched.
OpenCVE Enrichment