CVE-2025-20642: Medium severity android vulnerability
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2057.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20642?
CVE-2025-20642 is classified as having a moderate severity due to its potential for local privilege escalation with user interaction required for exploitation.
How do I fix CVE-2025-20642?
To fix CVE-2025-20642, apply the patch identified as ALPS09291146 provided by the vendor.
Who is affected by CVE-2025-20642?
CVE-2025-20642 affects Google Android versions 12.0, 13.0, 14.0, and 15.0.
What potential impact does CVE-2025-20642 have on users?
CVE-2025-20642 could lead to local escalation of privilege on affected devices if an attacker gains physical access.
Is user interaction necessary for exploiting CVE-2025-20642?
Yes, user interaction is necessary for the exploitation of CVE-2025-20642.