Impact
The vulnerability is a race condition in the Audio HAL component that can render the system unresponsive. An attacker with local user privileges could trigger the race condition without needing additional interaction, leading to a loss of availability. The flaw does not expose confidential data or alter system integrity, but it disrupts audio services and overall system responsiveness.
Affected Systems
MediaTek chipsets, including MT6880, MT6890, MT6990, MT6988, MT2735, and MT2737, are affected. The issue resides specifically in the Audio HAL of these devices.
Risk and Exploitability
Because the flaw requires user‑level execution on the device and no external network interaction, the risk is moderate. The EPSS score is < 1%, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be local, meaning an attacker must have access to the device or user involvement, which lowers the probability of widespread exploitation. The CVSS score is 5.5, indicating moderate severity.
OpenCVE Enrichment