Impact
The vulnerability arises from a missing bounds check in the neuropilot component of MediaTek chipsets, allowing an out‑of‑bounds write. This flaw can corrupt memory and give an attacker local escalation of privilege without needing additional execution rights. Because no user interaction is required, any process with access to the affected component can exploit the issue, potentially compromising device integrity.
Affected Systems
MediaTek chipsets are affected. The vendor does not list specific firmware or hardware revisions in the advisory, so affected versions are unknown at this time; users should verify that their device is running an unsupported firmware version that lacks the patch.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV. Nonetheless, the defect presents a high risk, as it enables local privilege escalation. The likely attack vector is local exploitation of the neuropilot component; the exploitation requires no user interaction but does not need elevated permissions to trigger the out‑of‑bounds write.
OpenCVE Enrichment