In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09486425; Issue ID: MSV-2609.
2025-04-07T04:15:19.577
2025-04-18T16:11:52.513
Analyzed
CVSSv3.1: 6.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | android | 12.0 | Yes | |
Operating System | android | 15.0 | Yes | |
Hardware | mediatek | mt6765 | - | No |
Hardware | mediatek | mt6768 | - | No |
Hardware | mediatek | mt6781 | - | No |
Hardware | mediatek | mt6789 | - | No |
Hardware | mediatek | mt6833 | - | No |
Hardware | mediatek | mt6853 | - | No |
Hardware | mediatek | mt6877 | - | No |
Hardware | mediatek | mt6885 | - | No |
Hardware | mediatek | mt8768 | - | No |
Hardware | mediatek | mt8771 | - | No |
Hardware | mediatek | mt8781 | - | No |
Hardware | mediatek | mt8786 | - | No |
Hardware | mediatek | mt8791t | - | No |