Impact
Audio HAL has an input validation flaw classified as CWE-307, which may allow a local user with system privileges to gain higher privileges. Exploitation requires no user interaction and can lead to code execution with elevated rights.
Affected Systems
Affected components are MediaTek chipsets used in devices. No specific firmware or chipset versions are listed in the advisory, so any device running the current Audio HAL without the mentioned patch is potentially vulnerable.
Risk and Exploitability
The CVSS score is 6.7, and the EPSS score is < 1%. The vulnerability is listed as a local privilege escalation that can be leveraged by a malicious actor who has already obtained system-level access. Because no user interaction is required, the risk is confined to local environments, and the vulnerability is not currently listed in the CISA KEV catalog. Apply the vendor patch ALPS11087540 as it resolves the issue.
OpenCVE Enrichment