Out of Bounds Write Vulnerability in Bluetooth by MediaTek
CVE-2022-21767
8.8HIGH
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 6 July 2022
What is CVE-2022-21767?
The vulnerability identified in Bluetooth implementations by MediaTek arises from a missing bounds check, which allows for a possible out of bounds write condition. Such a flaw may facilitate local escalation of privilege without requiring additional execution privileges. Exploitation of this vulnerability does not necessitate user interaction, posing a significant security risk for affected devices. This issue has been documented with Patch ID ALPS06784430.
Affected Version(s)
MT8167, MT8175, MT8183, MT8362A, MT8365, MT8385 Android 8.1, 9.0, 10.0, 11.0, 12.0