Impact
A missing permission check in the Telephony component of MediaTek chipsets allows a local attacker to elevate privileges without needing to execute any additional code or interact with the system. The flaw enables the attacker to assume higher authority within the device, potentially granting them full control over the operating environment. The weakness corresponds to CWE‑862, indicating an authorization failure that directly compromises integrity and confidentiality for the affected device.
Affected Systems
All devices that incorporate MediaTek chipsets using the Telephony stack are potentially vulnerable. No specific firmware or hardware version information is provided, so any MediaTek‑powered device that implements the affected Telephony code may be affected.
Risk and Exploitability
The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 7.7, indicating a high severity. This low exploitation probability suggests limited likelihood of widespread attacks, yet the absence of a permission check and the lack of user interaction requirement mean that any local user with access to the device could exploit the flaw immediately. The vulnerability can be triggered locally by a privileged or non‑privileged user with access to device functions, implying significant risk for devices in untrusted environments.
OpenCVE Enrichment