Impact
The vulnerability resides in the Audio HAL component of MediaTek chipsets, where a missing permission check allows a local attacker who already holds system privileges to read confidential data. This information disclosure does not require any user interaction and is a classic example of a privilege escalation flaw, classified as CWE-307.
Affected Systems
Affected systems are devices that use MediaTek chipsets running the current Audio HAL implementation; specific firmware versions are not disclosed, so any device employing the latest HAL may be vulnerable.
Risk and Exploitability
The risk of exploitation is limited to local hosts where an attacker can elevate to system privilege. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploitation yet. Based on the description, it is inferred that the attacker must already possess system privilege to exploit the flaw. The CVSS score of 4.4 indicates low to moderate severity, but local disclosure could compromise the confidentiality of stored audio metadata or recordings.
OpenCVE Enrichment