Impact
In the imgsensor component of MediaTek chipsets, a flaw in error handling can cause the application to crash. If a malicious actor can trigger this crash while already holding System privilege, the flaw can lead to local privilege escalation. The weakness involves improper release of a security‑relevant resource, classified as CWE‑754.
Affected Systems
The vulnerability affects all MediaTek chipsets that include the imgsensor driver. No specific product or firmware version information is available from the public data, so all deployments using this component should be treated as potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate‑high severity. The EPSS score is < 1%, indicating a very low but still nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the flaw enables local privilege escalation without requiring user interaction, meaning a local attacker with some privileged access could elevate their rights. Because no public exploit has been disclosed, the current risk is theoretical, but the lack of a user‑interaction requirement and the high impact of privilege escalation advise prompt remediation.
OpenCVE Enrichment