In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09924201; Issue ID: MSV-3820.
References
Link | Resource |
---|---|
https://corp.mediatek.com/product-security-bulletin/September-2025 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
03 Sep 2025, 16:06
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8792:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8775:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8676:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8788e:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8893:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt2718:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8786:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6899:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6991:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8196:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8883:-:*:*:*:*:*:*:* |
|
References | () https://corp.mediatek.com/product-security-bulletin/September-2025 - Vendor Advisory | |
First Time |
Mediatek mt6893
Mediatek mt8883 Mediatek mt6877 Mediatek mt8788e Mediatek Mediatek mt8786 Mediatek mt8676 Mediatek mt2718 Mediatek mt8678 Mediatek mt6899 Mediatek mt8792 Mediatek mt8893 Mediatek mt8796 Mediatek mt8196 Mediatek mt6853 Mediatek mt6991 Mediatek mt8775 Mediatek mt8791t Google android |
02 Sep 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.7 |
01 Sep 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-01 06:15
Updated : 2025-09-03 16:06
NVD link : CVE-2025-20707
Mitre link : CVE-2025-20707
CVE.ORG link : CVE-2025-20707
JSON object : View
Products Affected
- android
mediatek
- mt6877
- mt8775
- mt6853
- mt8786
- mt6899
- mt8791t
- mt8893
- mt8796
- mt8883
- mt8788e
- mt2718
- mt8196
- mt8792
- mt8676
- mt6991
- mt8678
- mt6893
CWE
CWE-416
Use After Free