Out of Bounds Write Vulnerability in MediaTek Products
CVE-2025-20783

6.7MEDIUM

What is CVE-2025-20783?

This vulnerability involves a possible out of bounds write in MediaTek's system software due to the absence of essential bounds checks. It allows an attacker, who has already acquired system-level privileges, to escalate their privileges locally without the need for user interaction. This could ultimately result in unauthorized access and control over the affected system. To mitigate this risk, applying the relevant security patch (Patch ID: ALPS10182882) is crucial.

Affected Version(s)

MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6897, MT6899, MT6983, MT6985, MT6989, MT6991, MT8186, MT8188, MT8196, MT8667, MT8673, MT8676, MT8678, MT8765, MT8766, MT8768, MT8771, MT8781, MT8791T, MT8792, MT8793, MT8795T, MT8796, MT8798, MT8873, MT8883 Android 14.0, 15.0, 16.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20783 : Out of Bounds Write Vulnerability in MediaTek Products