CVE-2023-20754
Description
In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07563028; Issue ID: ALPS07588343.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Integer overflow in MediaTek keyinstall allows local privilege escalation via out-of-bounds write with System execution privileges.
Vulnerability
In the keyinstall component of MediaTek chipsets, an integer overflow (CWE-190) can lead to an out-of-bounds write. The vulnerability exists in multiple chipsets including MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, and others [1]. Exploitation requires System execution privileges, and no user interaction is needed. The issue is identified by Patch ID ALPS07563028 and Issue ID ALPS07588343.
Exploitation
An attacker with System execution privileges can trigger the integer overflow in keyinstall, causing an out-of-bounds write. The exact sequence of operations is not publicly detailed, but the overflow occurs during key installation processing. No user interaction is required, and the attacker can execute the exploit locally on the device.
Impact
Successful exploitation leads to local escalation of privilege (EoP). Although the attacker already has System execution privileges, the out-of-bounds write can corrupt kernel memory or other critical structures, potentially allowing full compromise of the device or access to sensitive data [1].
Mitigation
MediaTek has provided patches to device OEMs as part of the July 2023 security bulletin [1]. The patch ID is ALPS07563028. OEMs are expected to incorporate the fix into their firmware updates. Users should apply updates from their device manufacturer when available. No workaround is documented, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- MediaTek, Inc./MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985, MT8185, MT8321, MT8385, MT8666, MT8667, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797v5Range: Android 11.0, 12.0, 13.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.