Out of Bounds Write Vulnerability in MediaTek Battery Products
CVE-2025-20798

7.8HIGH

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
6 January 2026

What is CVE-2025-20798?

A security vulnerability has been identified in MediaTek's battery products, where a potential out of bounds write exists due to a missing bounds check. This can enable a malicious actor with system privileges to escalate their access without requiring any user interaction, exposing critical systems to further threats. Users of affected MediaTek battery versions should apply the necessary updates as outlined in the security bulletin to mitigate this risk.

Affected Version(s)

MediaTek chipset MT2718

MediaTek chipset MT6765

MediaTek chipset MT6768

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.