Impact
The vulnerability resides in the Trusted Firmware‑A component of MediaTek chipsets, where a missing permission check can expose sensitive local information. An attacker who has already obtained System privilege can exploit this flaw without requiring any user interaction or additional setup. The weakness matches the category of Information Exposure to Unauthorized Users (CWE‑201).
Affected Systems
The affected product is the MediaTek chipset line supplied by MediaTek, Inc. No specific firmware or hardware revision numbers are published in the advisory, so all current deployments using the identified TFA code are potentially impacted.
Risk and Exploitability
Because the attack requires local System privileges, it is limited to environments where an attacker can already compromise privileged processes. However, once such privileges are present, the disclosure can occur immediately, with no additional user action or network interaction. The CVSS score of 4.4 indicates moderate severity, and the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no public exploits are known yet, but the absence of such data does not mitigate the need for patching when privileged access is possible.
OpenCVE Enrichment