CVE-2025-20657

In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09486425; Issue ID: MSV-2609.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt6765:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6781:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6789:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6885:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8771:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8786:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*

History

18 Apr 2025, 16:11

Type Values Removed Values Added
CPE cpe:2.3:h:mediatek:mt6768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8786:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6885:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6789:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8771:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6781:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6765:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*
References () https://corp.mediatek.com/product-security-bulletin/April-2025 - () https://corp.mediatek.com/product-security-bulletin/April-2025 - Vendor Advisory
First Time Mediatek mt8781
Mediatek mt6885
Mediatek mt6833
Mediatek mt6877
Mediatek mt6853
Mediatek mt6781
Mediatek mt6789
Mediatek
Mediatek mt6765
Mediatek mt8786
Google
Mediatek mt8791t
Mediatek mt8771
Mediatek mt8768
Google android
Mediatek mt6768

09 Apr 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.7

07 Apr 2025, 14:17

Type Values Removed Values Added
Summary
  • (es) En vdec, existe una posible omisión de permisos debido a una validación de entrada incorrecta. Esto podría provocar una escalada local de privilegios si un actor malicioso ya ha obtenido el privilegio de System. No se requiere la interacción del usuario para la explotación. ID de parche: ALPS09486425; ID de problema: MSV-2609.

07 Apr 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-07 04:15

Updated : 2025-04-18 16:11


NVD link : CVE-2025-20657

Mitre link : CVE-2025-20657

CVE.ORG link : CVE-2025-20657


JSON object : View

Products Affected

mediatek

  • mt8786
  • mt8771
  • mt8768
  • mt8781
  • mt6853
  • mt6885
  • mt6768
  • mt6765
  • mt6781
  • mt6789
  • mt6833
  • mt6877
  • mt8791t

google

  • android
CWE
CWE-787

Out-of-bounds Write