CVE-2025-20639: Medium severity android vulnerability
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2060.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20639?
The severity of CVE-2025-20639 is classified as moderate due to the potential for local escalation of privilege if physical access is obtained.
How do I fix CVE-2025-20639?
To fix CVE-2025-20639, users should apply the provided patch ID ALPS09291146 as soon as it becomes available.
Who is affected by CVE-2025-20639?
CVE-2025-20639 affects devices running Google Android versions 12.0, 13.0, 14.0, and 15.0.
Is user interaction required for CVE-2025-20639 exploitation?
Yes, user interaction is necessary for the exploitation of CVE-2025-20639, as it involves a local attack.
What are the potential consequences of CVE-2025-20639?
The potential consequences of CVE-2025-20639 include unauthorized access and escalation of privileges on vulnerable devices.