In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998901; Issue ID: MSV-1602.
The vulnerability results from inadequate input data validation in the WLAN driver (CWE-787 — out of bounds write). An attacker can send crafted network data that causes writes outside the designated memory area. Since the attack is possible over the network (AV:N), without required privileges (PR:N) and without user interaction (UI:N), the attack surface is very wide. Successful exploitation of the vulnerability can lead to device takeover.
An attacker can remotely execute arbitrary code on a vulnerable device, gaining full access to the confidentiality, integrity, and availability of the system (CVSS scores C:H/I:H/A:H).
The patch with identifier ALPS08998901 (Issue ID: MSV-1602) available from the manufacturer must be applied. Detailed information about versions containing the fix can be found in the MediaTek security bulletin: https://corp.mediatek.com/product-security-bulletin/October-2024
MediaTek SDK, Google Android (versions indicated in manufacturer references), and the MediaTek MT3605 chip — detailed versions available in the MediaTek security bulletin from October 2024.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGoogle Android
OSGoogle13.014.015.0Mediatek Mt3605
HWMediatekall versionsMediatek Mt6985
HWMediatekall versionsMediatek Mt6989
HWMediatekall versionsMediatek Mt6990
HWMediatekall versionsMediatek Mt7927
HWMediatekall versionsMediatek Mt8183
HWMediatekall versionsMediatek Mt8512
HWMediatekall versionsMediatek Mt8676
HWMediatekall versionsMediatek Mt8678
HWMediatekall versionsMediatek Mt8695
HWMediatekall versionsMediatek Mt8698
HWMediatekall versionsMediatek Mt8755
HWMediatekall versionsMediatek Mt8775
HWMediatekall versionsMediatek Mt8792
HWMediatekall versionsMediatek Mt8796
HWMediatekall versionsMediatek Software Development Kit
APPMediatek≤ 3.3
Related vulnerabilities
Heap buffer overflow w Google Chrome na Android — sandbox escape
Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku
Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever...
Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lev...
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local at...