Out-of-bounds write in MediaTek products - CVE-2025-20645

 

Out-of-bounds write in MediaTek products - CVE-2025-20645

Published: March 3, 2025


Vulnerability identifier: #VU105187
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20645
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to a missing bounds check within KeyInstall. A local application can execute arbitrary code.


Affected software

MT6765
MT6768
MT6833
MT6835
MT6855
MT6879
MT6886
MT6897
MT6983
MT6985
MT6989
MT8796
Samsung Mobile Firmware
MT6853
MT6893
Google Android

How to mitigate CVE-2025-20645

Install security update from vendor's website.

Samsung Mobile Firmware - update to SMR-APR-2025
Google Android - addressed in versions 12L 2025-03-05, 12 2025-03-05, 13 2025-03-05, 14 2025-03-05, 15 2025-03-05

External References

Related Security Bulletins