Impact
The vulnerability is a use‑after‑free in the Audio HAL of MediaTek chipsets, allowing an attacker who already has local System privileges to manipulate internal data after a memory block has been freed. This misuse can lead to local privilege escalation without any user interaction, giving the attacker full control over the device.
Affected Systems
MediaTek chipsets, identified by MediaTek, Inc. The specific Audio HAL component is affected. No explicit version information was provided, so all revisions that include the vulnerable Audio HAL code are potentially impacted.
Risk and Exploitability
The EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, indicating it has not been observed in the wild. The CVSS score is 6.7, which reflects a medium severity for a use‑after‑free that permits local privilege escalation. Attackers would need to compromise the device first to obtain System privileges or exploit another vector to gain them. Once those conditions are met, exploitation of this flaw is straightforward.
OpenCVE Enrichment