MediaTek Chipsets Display Component Use-After-Free Vulnerability Leading to Local Denial-of-Service

Vulnerability

A use-after-free vulnerability has been identified in the display component of certain MediaTek chipsets, including MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6897, MT6899, MT6983, MT6985, MT6989, MT6991, MT6993, MT8186, MT8188, MT8196, MT8667, MT8673, MT8676, MT8678, MT8765, MT8766, MT8768, MT8771, MT8781, MT8791T, MT8792, MT8793, MT8795T, MT8796, MT8798, MT8873, MT8883. This vulnerability can cause a system crash, leading to a local denial-of-service condition, but requires the attacker to have already obtained system privileges. Exploitation does not require user interaction.

Impact

Exploitation of this vulnerability can cause a system crash, leading to a local denial-of-service condition.

Remediation

MediaTek has issued a patch for this vulnerability, which can be applied by device manufacturers. The patch ID is ALPS10436998.

Added: Mar 2, 2026, 9:44 AM
Updated: Mar 2, 2026, 2:26 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.8
exploitability
2.8
remediation
0.0
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.