Out of Bounds Write Vulnerability in MediaTek Device
CVE-2025-20642

6.6MEDIUM

Summary

An out of bounds write vulnerability has been identified in MediaTek devices, stemming from a missing bounds check. This flaw allows an attacker with physical access to potentially escalate privileges locally, posing a risk to device security. It's important to note that user interaction is required for the exploitation of this vulnerability. MediaTek has issued a patch to address this issue, ensuring users can secure their devices against potential threats. Detailed mitigation steps can be found in the security bulletin.

Affected Version(s)

MT6739, MT6761, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6833, MT6853, MT6873, MT6877, MT6885, MT6893, MT8167, MT8167S, MT8175, MT8185, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8395, MT8666, MT8667, MT8673, MT8675, MT8678, MT8765, MT8766, MT8768, MT8771, MT8775, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8795T, MT8797, MT8798, MT8893 Android 12.0, 13.0, 14.0, 15.0

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.