In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10089545; Issue ID: MSV-4279.
2025-10-14T10:15:36.923
2025-10-15T18:45:16.163
Analyzed
CVSSv3.1: 7.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mediatek | iot_yocto | 25.0 | Yes |
| Operating System | android | 13.0 | Yes | |
| Operating System | android | 14.0 | Yes | |
| Operating System | android | 15.0 | Yes | |
| Operating System | android | 16.0 | Yes | |
| Hardware | mediatek | mt6886 | - | No |
| Hardware | mediatek | mt6897 | - | No |
| Hardware | mediatek | mt6899 | - | No |
| Hardware | mediatek | mt6985 | - | No |
| Hardware | mediatek | mt6989 | - | No |
| Hardware | mediatek | mt6991 | - | No |
| Hardware | mediatek | mt8195 | - | No |
| Hardware | mediatek | mt8196 | - | No |
| Hardware | mediatek | mt8370 | - | No |
| Hardware | mediatek | mt8390 | - | No |
| Hardware | mediatek | mt8395 | - | No |
| Hardware | mediatek | mt8792 | - | No |
| Hardware | mediatek | mt8793 | - | No |