In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389045 / ALPS09136494; Issue ID: MSV-1796.
The bug results from improper input data validation in WLAN station firmware (CWE-787 — out-of-bounds write). An attacker located near the victim (within wireless network range) can deliver specially crafted data that causes a write outside buffer boundaries. The exploit requires no privileges or user action.
An attacker can gain full remote code execution (RCE) on the victim's device without needing any privileges. This results in potential takeover of the system, breach of confidentiality, integrity, and availability of data.
Security patches available from the manufacturer should be applied according to references — MediaTek security bulletin from January 2025 (https://corp.mediatek.com/product-security-bulletin/January-2025). Patch ID: WCNCR00389045 / ALPS09136494.
Devices with MediaTek chipsets equipped with vulnerable WLAN STA FW software: Linux Foundation Yocto, MediaTek Software Development Kit (SDK), and Google Android — specific versions indicated in the manufacturer's security bulletin from January 2025 (Patch ID: WCNCR00389045 / ALPS09136494, Issue ID: MSV-1796)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGoogle Android
OSGoogle13.014.015.0Linuxfoundation Yocto
APPLinuxfoundation3.34.05.0Mediatek Mt3603
HWMediatekall versionsMediatek Mt6835
HWMediatekall versionsMediatek Mt6878
HWMediatekall versionsMediatek Mt6886
HWMediatekall versionsMediatek Mt6897
HWMediatekall versionsMediatek Mt7902
HWMediatekall versionsMediatek Mt7920
HWMediatekall versionsMediatek Mt7922
HWMediatekall versionsMediatek Mt8518s
HWMediatekall versionsMediatek Mt8532
HWMediatekall versionsMediatek Mt8766
HWMediatekall versionsMediatek Mt8768
HWMediatekall versionsMediatek Mt8775
HWMediatekall versionsMediatek Mt8796
HWMediatekall versionsMediatek Mt8798
HWMediatekall versionsMediatek Software Development Kit
APPMediatek≤ 2.4
Related vulnerabilities
Heap buffer overflow w Google Chrome na Android — sandbox escape
Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku
Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever...
Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lev...
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local at...