MediaTek Modem Privilege Escalation Vulnerability via Out-of-Bounds Write

Vulnerability

A privilege escalation vulnerability has been identified in the Modem component of certain MediaTek chipsets. This issue arises from an out-of-bounds write caused by an incorrect bounds check, potentially allowing a user equipment (UE) to escalate privileges if connected to a rogue base station controlled by an attacker. Notably, no additional execution privileges are required for exploitation, and user interaction is not needed.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation on the affected device.

Remediation

MediaTek has issued a patch for this vulnerability, which can be applied by device manufacturers. The patch ID is MOLY01672598.

Added: Nov 4, 2025, 7:47 AM
Updated: Nov 4, 2025, 7:47 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
5.0
exploitability
4.7
remediation
0.0
relevance
0.9
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.