CVE-2025-20641: High severity android vulnerability
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2058.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20641?
CVE-2025-20641 has a medium severity rating as it can lead to local escalation of privilege when an attacker has physical access to the device.
How do I fix CVE-2025-20641?
To fix CVE-2025-20641, apply the patch identified by ALPS09291146 as soon as possible.
Which versions of Android are affected by CVE-2025-20641?
CVE-2025-20641 affects Google Android versions 12.0, 13.0, 14.0, and 15.0.
What type of attack is associated with CVE-2025-20641?
CVE-2025-20641 is associated with a potential out of bounds write attack that requires user interaction for exploitation.
Is physical access required to exploit CVE-2025-20641?
Yes, CVE-2025-20641 requires physical access to the device for an attacker to exploit the vulnerability.