In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08810810 / ALPS08805789; Issue ID: MSV-1502.
The vulnerability (CWE-787) consists of writing data outside the allocated memory area in the venc component (video encoder). Lack of buffer boundary checks allows exceeding the write range, which can result in overwriting critical data structures in memory. Exploitation requires System execution privileges, but does not require any user interaction.
An attacker with System execution privileges can achieve local privilege escalation, potentially gaining full control over the device's operating system.
Apply patches available from the manufacturer according to the references. Patch identifiers: ALPS08810810 / ALPS08805789 (Issue ID: MSV-1502), published in the MediaTek security bulletin for August (August 2024).
Google Android on devices with MediaTek chipsets: MT6765, MT6768, MT6779, MT6785
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGoogle Android
OSGoogle12.0Mediatek Mt6765
HWMediatekall versionsMediatek Mt6768
HWMediatekall versionsMediatek Mt6779
HWMediatekall versionsMediatek Mt6785
HWMediatekall versionsMediatek Mt8321
HWMediatekall versionsMediatek Mt8385
HWMediatekall versionsMediatek Mt8666
HWMediatekall versionsMediatek Mt8667
HWMediatekall versionsMediatek Mt8755
HWMediatekall versionsMediatek Mt8765
HWMediatekall versionsMediatek Mt8766
HWMediatekall versionsMediatek Mt8768
HWMediatekall versionsMediatek Mt8771
HWMediatekall versionsMediatek Mt8775
HWMediatekall versionsMediatek Mt8781
HWMediatekall versionsMediatek Mt8786
HWMediatekall versionsMediatek Mt8788
HWMediatekall versionsMediatek Mt8789
HWMediatekall versionsMediatek Mt8791t
HWMediatekall versionsMediatek Mt8792
HWMediatekall versionsMediatek Mt8795t
HWMediatekall versionsMediatek Mt8796
HWMediatekall versionsMediatek Mt8797
HWMediatekall versionsMediatek Mt8798
HWMediatekall versions
Related vulnerabilities
Heap buffer overflow w Google Chrome na Android — sandbox escape
Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku
Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever...
Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lev...
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local at...