Impact
A missing bounds check in MediaTek's geniezone component can allow an attacker with System privilege to read memory beyond its intended bounds, potentially revealing sensitive data. The vulnerability requires local execution and a user action to trigger the exploit; remote access alone is insufficient. The impact is limited to information disclosure rather than code execution or denial of service as the flaw does not allow arbitrary code execution or disabling of geniezone.
Affected Systems
The affected product is MediaTek, Inc.’s chipset family, specifically the geniezone component of the chipset. The manufacturer has released security patches identified as ALPS10867524 and ALPS10876355 to address the flaw. No additional version details are provided in the CVE entry.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, indicating no large‑scale exploitation has been observed. Exploitation still requires the attacker to obtain System privilege, which limits the attacker's reach to devices where such privilege is granted. Because a user interaction is required, the likelihood of successful exploitation depends on the local environment and whether the attacker can persuade or trick a user into executing the malicious payload. The overall risk is moderate, with potential for local confidentiality compromise but no known widespread impact.
OpenCVE Enrichment