Impact
A use‑after‑free bug in MediaTek’s geniezone component permits an attacker who already has System privilege to gain additional escalated privileges locally. The flaw arises when a freed memory reference is accessed, allowing the attacker to manipulate protected resources. The lack of required user interaction means a local attacker can exploit the weakness directly from the device environment.
Affected Systems
MediaTek, Inc. equipment running the geniezone module on MediaTek chipsets is affected. No specific version numbers are publicly documented in the available information, so all current chipset releases incorporating geniezone should be considered at risk until a patch is applied.
Risk and Exploitability
Because exploitation requires an attacker to already possess System level privilege, the threat is confined to local attackers and cannot be leveraged remotely. The vulnerability is not listed in CISA’s KEV and there is no EPSS score, indicating limited availability of known exploits. The CVSS score of 6.7 indicates a moderate severity, while the use‑after‑free nature and the potential to elevate privilege still make it a high‑risk flaw for any system where privileged processes may be compromised. Vendors should treat this as a critical patchable issue and users should not rely on this for their security posture.
OpenCVE Enrichment