Memory Corruption Vulnerability in Mediatek Display Products
CVE-2025-20770

6.7MEDIUM

What is CVE-2025-20770?

A memory corruption vulnerability exists in Mediatek display products due to a use after free condition. This flaw can lead to local privilege escalation when a malicious actor already has system-level access. The exploitation of this vulnerability does not require any user interaction, increasing its risk profile. Affected users should apply updates as per Patch ID ALPS10196993 to safeguard their systems against potential exploitation.

Affected Version(s)

MT2718, MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6897, MT6899, MT6983, MT6985, MT6989, MT6991, MT8196, MT8676, MT8678, MT8792, MT8793 Android 14.0, 15.0, 16.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20770 : Memory Corruption Vulnerability in Mediatek Display Products