Out of Bounds Write Vulnerability in MediaTek Thermal Software
CVE-2025-20671
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 5 May 2025
What is CVE-2025-20671?
The vulnerability in MediaTek's thermal software is caused by a race condition, potentially allowing an out of bounds write. A malicious actor with system privileges could exploit this weakness to escalate their privileges without user interaction. A patch has been issued to address the issue, denoted by Patch ID: ALPS09698599 and Issue ID: MSV-3228. Organizations using MediaTek products should apply the available patches to mitigate risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MT2718, MT6878, MT6897, MT6899, MT6989, MT6991, MT8196, MT8391, MT8676, MT8678 Android 14.0, 15.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
