Out of Bounds Read Vulnerability in MediaTek Devices
CVE-2025-20643

3.9LOW

Summary

A potential out of bounds read vulnerability exists in certain MediaTek devices due to an insufficient bounds check. If exploited, this vulnerability could allow a malicious actor with physical access to the device to disclose sensitive information, especially if they have already gained System privileges. User interaction is required for the successful exploitation of this issue. For further details and mitigation steps, refer to the security bulletin issued by MediaTek.

Affected Version(s)

MT6739, MT6761, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6833, MT6853, MT6873, MT6877, MT6885, MT6893, MT8167, MT8167S, MT8175, MT8185, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8395, MT8666, MT8667, MT8673, MT8675, MT8678, MT8765, MT8766, MT8768, MT8771, MT8775, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8795T, MT8797, MT8798, MT8893 Android 12.0, 13.0, 14.0, 15.0

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.