Out of Bounds Read Vulnerability in MediaTek Products
CVE-2025-20776

6.7MEDIUM

What is CVE-2025-20776?

This vulnerability allows for a potential out of bounds read due to inadequate bounds checking within the MediaTek software display functionality. A malicious actor, having already acquired System privileges, could exploit this flaw to elevate their access level further without any user interaction. The issue highlights the importance of robust security measures in software design. For remediation, users should update to the latest version as indicated in the patch documentation (Patch ID: ALPS10184297; Issue ID: MSV-4759).

Affected Version(s)

MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6897, MT6899, MT6983, MT6985, MT6989, MT6991, MT8186, MT8188, MT8196, MT8667, MT8673, MT8676, MT8678, MT8765, MT8766, MT8768, MT8771, MT8781, MT8791T, MT8792, MT8793, MT8795T, MT8796, MT8798, MT8873, MT8883 Android 14.0, 15.0, 16.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.