In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09924201; Issue ID: MSV-3820.
References
Link | Resource |
---|---|
https://corp.mediatek.com/product-security-bulletin/September-2025 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
03 Sep 2025, 16:06
Type | Values Removed | Values Added |
---|---|---|
First Time |
Google
Mediatek mt8791t Mediatek mt8786 Mediatek mt8893 Mediatek mt8775 Mediatek mt6893 Mediatek mt2718 Mediatek mt8792 Google android Mediatek mt8883 Mediatek mt8676 Mediatek mt6877 Mediatek mt6899 Mediatek mt8796 Mediatek mt8196 Mediatek mt6991 Mediatek mt8678 Mediatek mt8788e Mediatek mt6853 Mediatek |
|
References | () https://corp.mediatek.com/product-security-bulletin/September-2025 - Vendor Advisory | |
CPE | cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8883:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8196:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8792:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8893:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt2718:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8676:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8788e:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6991:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6899:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8775:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8786:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* |
02 Sep 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.7 |
01 Sep 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-01 06:15
Updated : 2025-09-03 16:06
NVD link : CVE-2025-20707
Mitre link : CVE-2025-20707
CVE.ORG link : CVE-2025-20707
JSON object : View
Products Affected
mediatek
- mt8678
- mt8791t
- mt8788e
- mt8786
- mt8775
- mt6893
- mt6853
- mt8792
- mt8676
- mt8893
- mt8196
- mt6991
- mt2718
- mt8796
- mt6877
- mt8883
- mt6899
- android
CWE
CWE-416
Use After Free