Impact
MediaTek SurfaceFlinger contains a use‑after‑free memory corruption that may enable an attacker who already has System privilege to further compromise the system. The flaw is a classic CWE-416 condition that could allow corruption of critical heap objects.
Affected Systems
The vulnerability is reported for MediaTek, Inc. MediaTek chipsets. No specific firmware or software version ranges are disclosed in the CVE data.
Risk and Exploitability
The flaw requires local access with System privileges and does not require user interaction. An attacker who can exercise System privilege can exploit the use‑after‑free to elevate control, potentially taking full system control. The CVSS score is 6.7, indicating a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The absence of an exploit probability metric suggests uncertainty about how often it has been leveraged, but the combination of local privilege and ability to corrupt memory makes the risk significant for environments where untrusted code can acquire System privileges.
OpenCVE Enrichment