In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09924201; Issue ID: MSV-3820.
History

Wed, 03 Sep 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Mediatek
Mediatek mt2718
Mediatek mt6853
Mediatek mt6877
Mediatek mt6893
Mediatek mt6899
Mediatek mt6991
Mediatek mt8196
Mediatek mt8676
Mediatek mt8678
Mediatek mt8775
Mediatek mt8786
Mediatek mt8788e
Mediatek mt8791t
Mediatek mt8792
Mediatek mt8796
Mediatek mt8883
Mediatek mt8893
CPEs cpe:2.3:h:mediatek:mt2718:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6899:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6991:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8196:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8676:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8775:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8786:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8788e:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8792:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8883:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8893:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
Vendors & Products Google
Google android
Mediatek
Mediatek mt2718
Mediatek mt6853
Mediatek mt6877
Mediatek mt6893
Mediatek mt6899
Mediatek mt6991
Mediatek mt8196
Mediatek mt8676
Mediatek mt8678
Mediatek mt8775
Mediatek mt8786
Mediatek mt8788e
Mediatek mt8791t
Mediatek mt8792
Mediatek mt8796
Mediatek mt8883
Mediatek mt8893

Tue, 02 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 01 Sep 2025 05:30:00 +0000

Type Values Removed Values Added
Description In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09924201; Issue ID: MSV-3820.
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published: 2025-09-01T05:12:24.351Z

Updated: 2025-09-03T03:55:25.732Z

Reserved: 2024-11-01T01:21:50.383Z

Link: CVE-2025-20707

cve-icon Vulnrichment

Updated: 2025-09-02T13:01:44.150Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-01T06:15:35.123

Modified: 2025-09-03T16:06:46.333

Link: CVE-2025-20707

cve-icon Redhat

No data.