In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09924201; Issue ID: MSV-3820.
References
Link | Resource |
---|---|
https://corp.mediatek.com/product-security-bulletin/September-2025 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
03 Sep 2025, 16:06
Type | Values Removed | Values Added |
---|---|---|
References | () https://corp.mediatek.com/product-security-bulletin/September-2025 - Vendor Advisory | |
CPE | cpe:2.3:h:mediatek:mt2718:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6899:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8676:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8788e:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8196:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8775:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8786:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8792:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8883:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6991:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8893:-:*:*:*:*:*:*:* |
|
First Time |
Mediatek mt8792
Mediatek Mediatek mt8796 Mediatek mt6853 Mediatek mt8678 Mediatek mt2718 Google android Mediatek mt8791t Mediatek mt6991 Mediatek mt8676 Mediatek mt8893 Mediatek mt8786 Mediatek mt8775 Mediatek mt8788e Mediatek mt8883 Mediatek mt6893 Mediatek mt6899 Mediatek mt8196 Mediatek mt6877 |
02 Sep 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.7 |
01 Sep 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-01 06:15
Updated : 2025-09-03 16:06
NVD link : CVE-2025-20707
Mitre link : CVE-2025-20707
CVE.ORG link : CVE-2025-20707
JSON object : View
Products Affected
mediatek
- mt8796
- mt6893
- mt8678
- mt8196
- mt8792
- mt8786
- mt8893
- mt6853
- mt6877
- mt8791t
- mt6991
- mt8676
- mt8775
- mt8788e
- mt6899
- mt8883
- mt2718
- android
CWE
CWE-416
Use After Free