Out of Bounds Write Vulnerability in GNSS Service by MediaTek
CVE-2025-20746

Currently unrated

What is CVE-2025-20746?

The GNSS service in MediaTek devices is susceptible to an out of bounds write due to a flawed bounds check. This vulnerability enables a malicious actor with system privileges to escalate their access level further, without the need for user interaction. It is crucial for users to apply the available patches to mitigate potential exploits.

Affected Version(s)

MT2718, MT2737, MT6835, MT6878, MT6886, MT6897, MT6899, MT6982, MT6985, MT6986, MT6986D, MT6989, MT6990, MT6991, MT8676, MT8678, MT8755, MT8893 Android 14.0, 15.0 / openWRT 21.02, 23.05 / Yocto 4.0 / RDK-B 24Q1 / Zephyr 3.7.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20746 : Out of Bounds Write Vulnerability in GNSS Service by MediaTek