Memory Corruption Vulnerability in MediaTek Products
CVE-2025-20766

7.8HIGH

What is CVE-2025-20766?

In MediaTek products, a vulnerability exists due to improper input validation that could lead to memory corruption. This flaw potentially allows local escalation of privileges for an attacker who has already gained system-level access. Exploitation of this vulnerability does not require user interaction, making it a serious concern for security. It is crucial for users of affected MediaTek products to apply the necessary patches to mitigate this risk.

Affected Version(s)

MT2718, MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6897, MT6899, MT6983, MT6985, MT6989, MT6991, MT8196, MT8676, MT8678, MT8792, MT8793 Android 14.0, 15.0, 16.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.