Information Disclosure Vulnerability in MediaTek Devices
CVE-2025-20665
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 5 May 2025
What is CVE-2025-20665?
An information disclosure vulnerability exists in MediaTek's Devinfo due to the absence of a proper SELinux policy. This issue permits local information disclosure of device identifiers without requiring additional execution privileges or user interaction for exploitation. The flaw highlights the importance of comprehensive security policy implementations to safeguard sensitive information contained within the device.
Affected Version(s)
MT6580, MT6761, MT6765, MT6768, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6983, MT6985, MT8175, MT8195, MT8196, MT8321, MT8365, MT8370, MT8385, MT8390, MT8395, MT8666, MT8667, MT8673, MT8678, MT8765, MT8766, MT8768, MT8771, MT8775, MT8781, MT8786, MT8788, MT8788E, MT8789, MT8791T, MT8795T, MT8796, MT8797, MT8798, MT8893 Android 13.0, 14.0, 15.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved