CVE-2025-20640: Medium severity android vulnerability
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2059.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20640?
The severity of CVE-2025-20640 is considered medium due to its potential for local information disclosure.
How do I fix CVE-2025-20640?
To fix CVE-2025-20640, apply the patch provided in Patch ID ALPS09291146 to the affected device.
Who is affected by CVE-2025-20640?
CVE-2025-20640 affects Google Android versions 12.0, 13.0, 14.0, and 15.0.
Is user interaction required to exploit CVE-2025-20640?
Yes, user interaction is required for the exploitation of CVE-2025-20640.
What type of vulnerability is CVE-2025-20640?
CVE-2025-20640 is an out-of-bounds read vulnerability that can lead to local information disclosure.