CVE-2023-20654
Description
In keyinstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628168; Issue ID: ALPS07589148.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2023-20654: A missing bounds check in keyinstall allows out-of-bounds write, enabling local escalation of privilege with System privileges.
Vulnerability
In the keyinstall component of MediaTek chipsets, a missing bounds check leads to a possible out-of-bounds write. The vulnerability affects devices running Android with MediaTek chipsets and requires System execution privileges to be exploited. The issue is identified by Patch ID: ALPS07628168 and Issue ID: ALPS07589148. Affected chipsets include MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, and others, as detailed in the MediaTek Product Security Bulletin [1].
Exploitation
An attacker with System execution privileges can trigger the out-of-bounds write without any user interaction. This means that an already-privileged process or a local attacker who gains System-level access can exploit the vulnerability. The exploitation does not require network access or any special permissions beyond System privileges.
Impact
Successful exploitation leads to local escalation of privilege (EoP) within the System context. The out-of-bounds write could allow the attacker to corrupt memory, potentially leading to arbitrary code execution at the System level, which could result in full compromise of the device's security mechanisms.
Mitigation
MediaTek has released security patches addressing this vulnerability as part of the April 2023 Product Security Bulletin. Device OEMs are expected to provide these patches in their monthly firmware updates. Users should apply the latest security updates from their device manufacturer. No workarounds are available beyond patching.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- MediaTek, Inc./MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6889, MT6891, MT6893, MT6895, MT6983, MT8185, MT8192, MT8321, MT8385, MT8666, MT8667, MT8673, MT8675, MT8765, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8795T, MT8797, MT8798, MT8871, MT8891v5Range: Android 10.0, 11.0, 12.0, 13.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.