Memory Corruption Vulnerability in MediaTek Devices
CVE-2025-20772

6.7MEDIUM

What is CVE-2025-20772?

A memory corruption issue has been identified in MediaTek devices, caused by a use-after-free error. This vulnerability can potentially allow malicious actors to escalate privileges locally, provided they have already gained system-level access. Exploitation does not require user interaction, which increases the risk of unauthorized system control. Users are advised to apply patch ALPS10196993 to mitigate this security concern.

Affected Version(s)

MT2718, MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6897, MT6899, MT6983, MT6985, MT6989, MT6991, MT8196, MT8676, MT8678, MT8792, MT8793 Android 14.0, 15.0, 16.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.