MediaTek Chipsets MAE Component Privilege Escalation Vulnerability

Vulnerability

A race condition vulnerability in the MAE component of certain MediaTek chipsets can lead to a possible out-of-bounds write. This vulnerability could allow local escalation of privilege for an actor who has already obtained system privileges. The issue arises from a time-of-check time-of-use race condition, where the vulnerability can be exploited without user interaction.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a user with system privileges to gain elevated rights or access.

Remediation

MediaTek has issued a patch for this vulnerability, which can be applied by device manufacturers. Instructions for applying the patch are available through MediaTek's official channels.

Added: Mar 2, 2026, 9:28 AM
Updated: Mar 2, 2026, 2:26 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
2.4
remediation
7.9
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.