Impact
The vulnerability is a double‑free in camera middleware that can allow an attacker with existing System privilege to execute arbitrary actions with elevated rights. Because the flaw does not require user interaction, an adversary who has already compromised the device’s local security context can exploit it immediately. This creates a high‑impact security risk by enabling full control over the affected media building blocks.
Affected Systems
The flaw affects MediaTek, Inc. chipset devices that run the camera middleware referenced by the vendor. Exact firmware or hardware revision impacted is not specified, but all models deploying the vulnerable camera stack are susceptible.
Risk and Exploitability
With a CVSS score of 6.7, the vulnerability is nevertheless judged as high risk due to its local privilege escalation nature and lack of required user interaction. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits yet. The typical attack path would involve an attacker first gaining System privilege—perhaps by leveraging another vulnerability or by physical access—and then triggering the double‑free to elevate privileges further.
OpenCVE Enrichment