Out of Bounds Write Vulnerability in Mediatek Devices
CVE-2025-20641
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 3 February 2025
Summary
In certain Mediatek devices, a possible out of bounds write vulnerability has been identified due to a missing bounds check. This issue allows for potential local escalation of privilege if an attacker has physical access, without requiring any additional execution privileges. User interaction is necessary for successful exploitation, making it critical for users to apply patches to ensure their device security. For further details and remediation, consult the official Mediatek product security bulletin.
Affected Version(s)
MT6739, MT6761, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6833, MT6853, MT6873, MT6877, MT6885, MT6893, MT8167, MT8167S, MT8175, MT8185, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8395, MT8666, MT8667, MT8673, MT8675, MT8678, MT8765, MT8766, MT8768, MT8771, MT8775, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8795T, MT8797, MT8798, MT8893 Android 12.0, 13.0, 14.0, 15.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved