Impact
An integer overflow in the Mediatek display engine allows an out‑of‑bounds memory read. The flaw can reveal sensitive data stored within the device’s memory; the attacker must already have local system privileges to trigger the disclosure. No additional user interaction or network connectivity is required to exploit the vulnerability.
Affected Systems
The vulnerability affects all MediaTek, Inc. chipsets that incorporate the Mediatek display stack and have not applied the latest firmware update. No specific firmware or driver versions are listed, so any device using the affected stack is potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity vulnerability, while the EPSS score of <1% reflects a low but non‑zero probability of exploitation. The flaw remains local and requires that the attacker have already achieved system‑level access; no network or remote trigger is involved. Because the vulnerability is not listed in the CISA KEV catalog, widespread exploitation is considered unlikely in the current threat landscape.
OpenCVE Enrichment