Impact
The flaw resides in the Audio HAL component of MediaTek chipsets, where improper input validation can expose sensitive system data. An attacker who already possesses System‑level privileges can read protected information without needing user interaction, which can enable further compromise of the device.
Affected Systems
All MediaTek chipset devices that include the affected Audio HAL are potentially vulnerable. The advisory does not list specific firmware revisions or models, so any current MediaTek chipsets should be considered at risk until the patch is applied.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 4.4, indicating medium severity. Exploitation requires system privilege and can be carried out without user interaction, increasing the risk for devices that have already been compromised by privileged malware. The impact is a local disclosure of information, with no known public exploits documented.
OpenCVE Enrichment