MediaTek Modem Out-of-Bounds Write Vulnerability Leading to Remote Code Execution

Vulnerability

A critical out-of-bounds write vulnerability has been identified in the Modem component of various MediaTek chipsets. This issue arises from a missing bounds check, which could allow remote code execution. The vulnerability can be exploited if a user equipment (UE) connects to a rogue base station controlled by an attacker. Notably, no additional execution privileges are required for exploitation, and user interaction is not needed.

Impact

Exploitation of this vulnerability could lead to unauthorized remote code execution on the affected device.

Remediation

MediaTek has issued a patch for this vulnerability, identified by Patch ID MOLY00720348. Device OEMs can contact their MediaTek representative for further information.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
7.5
exploitability
4.7
remediation
7.7
relevance
0.0
threat
0.7
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.