Local Information Disclosure Vulnerability in MediaTek Devices
CVE-2025-20638
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 3 February 2025
Summary
A potential local information disclosure vulnerability has been identified in DA by MediaTek, stemming from uninitialized heap data. This flaw allows an attacker with physical access to the device to read sensitive uninitialized data, which could lead to unauthorized access to potentially sensitive information. Notably, user interaction is required to exploit this vulnerability. The issue has been documented with Patch ID: ALPS09291449 and Issue ID: MSV-2066.
Affected Version(s)
MT6739, MT6761, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6833, MT6853, MT6873, MT6877, MT6885, MT6893, MT8167, MT8167S, MT8175, MT8185, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8395, MT8666, MT8667, MT8673, MT8675, MT8678, MT8765, MT8766, MT8768, MT8771, MT8775, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8795T, MT8797, MT8798, MT8893 Android 12.0, 13.0, 14.0, 15.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved