In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2056.
The product fails to adequately prevent the revealing of unnecessary and potentially sensitive system information within debugging messages.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://corp.mediatek.com/product-security-bulletin/February-2025 | vendor advisory |