VYPR
Unrated severityNVD Advisory· Published Nov 8, 2022· Updated May 1, 2025

CVE-2022-32602

CVE-2022-32602

Description

In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388790; Issue ID: ALPS07388790.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An out-of-bounds read in MTK keyinstall allows local information disclosure without user interaction.

Vulnerability

In the keyinstall component on MediaTek chipsets, a missing bounds check leads to an out-of-bounds read vulnerability. The flaw is present in firmware versions prior to the patch identified by ALPS07388790. Affected chipsets include MT6739, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6889, MT6891, MT6893, MT6895, MT6983, MT8321, MT8385, MT8666, MT8675, MT8765, MT8766, MT8768, MT876 and others [1].

Exploitation

An attacker with local access to the device can exploit this vulnerability without any additional execution privileges or user interaction. The out-of-bounds read can be triggered by providing crafted input to the keyinstall component, which lacks proper bounds validation [1].

Impact

Successful exploitation results in reading memory outside the intended buffer, leading to local information disclosure. The attacker may obtain sensitive data from kernel or userspace memory, depending on the memory layout [1].

Mitigation

MediaTek released a security patch for this vulnerability, identified as ALPS07388790, in the November 2022 Product Security Bulletin [1]. Device OEMs should deploy the patch to affected chipsets. No workaround is provided, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of the publication date.

References
  1. November 2022

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • MediaTek, Inc./MT6833, MT6883, MT6983, MT8183, MT8185, MT8321, MT8385, MT8675, MT8765, MT8766, MT8768, MT8786, MT8789, MT8791, MT8791T, MT8797v5
    Range: Android 11.0, 12.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.