In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08737250; Issue ID: MSV-1452.
A CWE-843 type confusion error in the venc component causes data to be interpreted as a different type than it was allocated, enabling an out-of-bounds write to the allocated buffer memory. An attacker with System-level privileges can exploit this vulnerability without any user interaction. This results in the possibility of code execution with elevated privileges in the system context.
An attacker can cause local privilege escalation on the vulnerable device. Violation of confidentiality, integrity, and availability of the system is possible.
Apply patch with identifier ALPS08737250 (Issue ID: MSV-1452) available in the MediaTek security bulletin from July 2024. The update should be deployed according to the manufacturer's references: https://corp.mediatek.com/product-security-bulletin/July-2024
Devices running Google Android equipped with MediaTek MT6768 and MT6779 processors. Specific software versions are indicated in the manufacturer's references (MediaTek security bulletin from July 2024).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGoogle Android
OSGoogle12.013.014.0Mediatek Mt6768
HWMediatekall versionsMediatek Mt6779
HWMediatekall versionsMediatek Mt8321
HWMediatekall versionsMediatek Mt8385
HWMediatekall versionsMediatek Mt8755
HWMediatekall versionsMediatek Mt8765
HWMediatekall versionsMediatek Mt8766
HWMediatekall versionsMediatek Mt8768
HWMediatekall versionsMediatek Mt8771
HWMediatekall versionsMediatek Mt8775
HWMediatekall versionsMediatek Mt8781
HWMediatekall versionsMediatek Mt8786
HWMediatekall versionsMediatek Mt8788
HWMediatekall versionsMediatek Mt8789
HWMediatekall versionsMediatek Mt8791t
HWMediatekall versionsMediatek Mt8792
HWMediatekall versionsMediatek Mt8795t
HWMediatekall versionsMediatek Mt8796
HWMediatekall versionsMediatek Mt8797
HWMediatekall versionsMediatek Mt8798
HWMediatekall versions
Related vulnerabilities
Heap buffer overflow w Google Chrome na Android — sandbox escape
Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku
Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever...
Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lev...
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local at...