Table of Contents
This guide provides a clear, practical overview of new vulnerability on mediatek chip makes 30% of Android, with useful context, important details, and straightforward takeaways for everyday readers.
The vulnerabilities discovered by Check Point and three of them, CVE-2021-0661, CVE-2021-0662 and CVE-2021-0663 have been patched right in the October 2021 update MediaTek Security Bulletin. The fourth vulnerability, CVE-2021-0673, will be patched next month.
If you don't regularly install the latest security updates, newly discovered vulnerabilities on MediaTek chips will make Android smartphones vulnerable to eavesdropping attacks, malware infections or privilege escalation attacks.
Older smartphone models that no longer support security updates run the risk of not receiving MediaTek's patch.

Details of the vulnerability on the MediaTek chip
The new chipsets from MediaTek use a dedicated audio processor called Digital Signal Processor (DSP) to reduce CPU load and improve audio quality and performance.
The DSP receives audio processing requests from Android applications through the driver and the IPC system. Theoretically, an unprivileged application could exploit vulnerabilities to manipulate request processing and run code on the DSP.
The audio driver does not communicate directly with the DPS, but with IPI messages that are passed to the System Control Processor (SCP).
By reversing the Android API code responsible for audio communication, Check Point discovered the following vulnerabilities:
- CVE-2021-0661, CVE-2021-0662, and CVE-2021-0663: Incorrect bounds checks lead to out-of-bounds writes and local privilege escalation.
- CVE-2021-0673: Details will be revealed next month.
By combining these vulnerabilities, hackers can perform local privilege escalation attacks, send messages to the DSP firmware, and hide or run code on the DSP chip itself.
"Since the DSP firmware has access to the audio data stream, a malformed IPI message can be exploited by a hacker to escalate privileges and theoretically could eavesdrop on smartphone users," Check Point said. To share.
Because there is no patch for the CVE-2021-0673 vulnerability, MediaTek has removed the ability to use the parameter string command through AudioManager to reduce the possibility of exploitation.
If you are using an Android smartphone equipped with a MediaTek chip, you should consider updating its software as soon as possible.
Key Takeaways
Use the information above as a practical reference for new vulnerability on mediatek chip makes 30% of Android. Review each step carefully, confirm any requirements, and choose the option that best fits your situation.
FAQ
What does this guide explain about New Vulnerability on Mediatek Chip Makes 30% of Android?
It explains the main concepts, practical considerations, and useful steps related to new vulnerability on mediatek chip makes 30% of Android without requiring advanced knowledge.
Who can benefit from learning about New Vulnerability on Mediatek Chip Makes 30% of Android?
This information is useful for readers who want a clear overview, practical guidance, and reliable steps related to new vulnerability on mediatek chip makes 30% of Android.
What should I check before applying this information?
Review the requirements, confirm that your device, software, or situation matches the instructions, and back up important data before making major changes.
Reader Comments 0
Sign in with email or Google to join the discussion.