MediaTek PlayReady TA Out-of-Bounds Read Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability in the PlayReady Trusted Application (TA) component of MediaTek chipsets, specifically in the MT9972 chipset, has been identified. This issue arises from a missing bounds check, leading to a possible out-of-bounds read. Such a flaw could allow a malicious actor, who has already gained System privileges, to escalate privileges locally. The vulnerability does not require user interaction for exploitation. Affected software versions include Android 12.0 and 14.0.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a user with System privileges to gain elevated rights or access.

Remediation

MediaTek has issued a patch for this vulnerability, which can be applied by device manufacturers. Instructions for applying the patch are available through MediaTek's official channels.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
2.8
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.