# CVE-2023-32871

## Summary

- **CVE ID:** CVE-2023-32871
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-391
- **Published:** May 6, 2024
- **Last Modified:** Mar 13, 2026

## Description

In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Issue ID: ALPS08355514.

## Affected Products

- MediaTek, Inc. — MT2737, MT6739, MT6761, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6877, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6893, MT6895, MT6897, MT6980, MT6983, MT6985, MT6989, MT6990, MT8167, MT8167S, MT8168, MT8173, MT8175, MT8185, MT8188, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8390, MT8395, MT8755, MT8765, MT8766, MT8768, MT8775, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797, MT8798 (Android 11.0, 12.0, 13.0, 14.0 / OpenWrt 19.07, 21.02 / Yocto 3.3, 4.0 / RDK-B 22Q3)

## References

- [CNA](https://corp.mediatek.com/product-security-bulletin/May-2024)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.00%
- **EPSS Percentile:** 0.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._