MediaTek Bluetooth Firmware Reachable Assertion Vulnerability Leading to Remote Denial-of-Service

Vulnerability

A vulnerability has been identified in the Bluetooth firmware of certain MediaTek chipsets, including MT2737, MT3603, MT6835, MT6878, MT6886, MT6897, MT6985, MT6989, MT6990, MT7902, MT7920, MT7921, MT7922, MT7925, and MT8195. This vulnerability arises from improper exception handling, creating a possible reachable assertion. Exploitation of this vulnerability could lead to remote denial-of-service, causing a system hang or similar issue. Notably, no additional execution privileges are required for exploitation, and user interaction is not needed.

Impact

Exploitation of this vulnerability can cause a remote denial-of-service condition, leading to a system hang or similar issue.

Remediation

MediaTek has released patches for this vulnerability. Instructions for applying the patch can be obtained from the MediaTek Product Security Bulletin or through the MediaTek contact person for device OEMs.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
4.7
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.