In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09741871; Issue ID: MSV-3317.
The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://corp.mediatek.com/product-security-bulletin/July-2025 | vendor advisory |