In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; Issue ID: MSV-1603.
The WLAN driver contains an out-of-bounds write error (CWE-787) resulting from improper input validation. An attacker can deliver specially crafted network data that causes writing outside the intended memory area. The exploit requires no privileges on the device or user interaction, making the attack fully remote and hands-off.
Successful exploitation of this vulnerability can lead to complete takeover of the device through remote code execution (RCE) in the context of the WLAN driver, with potential access to sensitive data, ability to modify it, and disruption of system operation.
Apply patches available from the manufacturer according to the references (Patch ID: ALPS08998449; Issue ID: MSV-1603). Detailed information about affected versions and updates is available in the MediaTek security bulletin from October 2024: https://corp.mediatek.com/product-security-bulletin/October-2024
Devices based on MediaTek chipsets with systems: MediaTek IoT Yocto, MediaTek Software Development Kit (SDK), and Google Android (versions specified in the MediaTek security bulletin from October 2024)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGoogle Android
OSGoogle12.013.014.0Mediatek Iot Yocto
APPMediatek24.0Mediatek Mt3605
HWMediatekall versionsMediatek Mt6985
HWMediatekall versionsMediatek Mt6989
HWMediatekall versionsMediatek Mt6990
HWMediatekall versionsMediatek Mt7927
HWMediatekall versionsMediatek Mt8183
HWMediatekall versionsMediatek Mt8365
HWMediatekall versionsMediatek Mt8512
HWMediatekall versionsMediatek Mt8676
HWMediatekall versionsMediatek Mt8678
HWMediatekall versionsMediatek Mt8695
HWMediatekall versionsMediatek Mt8698
HWMediatekall versionsMediatek Mt8755
HWMediatekall versionsMediatek Mt8775
HWMediatekall versionsMediatek Mt8792
HWMediatekall versionsMediatek Mt8796
HWMediatekall versionsMediatek Software Development Kit
APPMediatek≤ 3.3
Related vulnerabilities
Heap buffer overflow w Google Chrome na Android — sandbox escape
Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku
Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever...
Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lev...
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local at...