CVE-2025-20645

CVE-2025-20645

Vendor Mediatek, Inc.
Product MT6765, MT6768, MT6833, MT6835, MT6853, MT6855, MT6879, MT6886, MT6893, MT6897, MT6983, MT6985, MT6989, MT8796
Weakness CWE-787
Published March 3, 2025
Last update February 26, 2026

CVSS base score

What the vulnerability does

01Description

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09475476; Issue ID: MSV-2599.

Key dates

02Disclosure timeline

March 3, 2025 CVE published
February 26, 2026 Record updated