Revisiting Userspace Reachability to Baseband Processors: A Forensic Analysis of MediaTek CCCI Interfaces on MT6765 Platforms
Description
This paper presents a forensic analysis of the Cross-Core Communication Interface (CCCI) driver on MediaTek MT6765 platforms, focusing on userspace reachability of modem-facing interfaces.
Experimental observations demonstrate that structured payloads sent via ioctl to /dev/ccci_ioctl0 produce correlated kernel log responses consistent with modem interaction, even when the device is in airplane mode.
While no exploitable vulnerability is claimed, the findings highlight a potentially broader-than-expected attack surface and raise important questions about security boundary definitions between the application processor and baseband processor.
This work contributes to the understanding of modem interface exposure in modern mobile systems and complements prior research focused on baseband-to-kernel attack vectors.
Files
Casarrubias_Baseband_Reachability_MT6765.pdf
Files
(307.3 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:2e03cb8b1faed2f2d58ae8ce112fcde2
|
307.3 kB | Preview Download |
Additional details
Dates
- Collected
-
2026-03-13/2026-03-24Research and analysis period