CVE-2025-20648: Medium severity android vulnerability
Published Mar 3, 2025
·Updated
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09456673; Issue ID: MSV-2584.
Affected Software
12 affected components
All of the following
Any of the following
Google Android=13.0
Google Android=14.0
Google Android=15.0
Any of the following
MediaTek Mt2718
MediaTek Mt6879
MediaTek Mt6989
MediaTek Mt8196
MediaTek Mt8370
MediaTek Mt8390
MediaTek Mt8395
MediaTek Mt8673
MediaTek Mt8678
Event History
Mar 3, 2025
CVE Published
via MITRE·02:25 AM
Data Sourced
via MITRE·02:25 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20648?
CVE-2025-20648 has a medium severity level due to a potential information disclosure risk.
2
How do I fix CVE-2025-20648?
To fix CVE-2025-20648, apply the patch identified as ALPS09456673.
3
What systems are affected by CVE-2025-20648?
CVE-2025-20648 affects Android versions 13.0, 14.0, and 15.0.
4
What exploitation conditions exist for CVE-2025-20648?
CVE-2025-20648 can be exploited without user interaction and does not require additional execution privileges.
5
What type of vulnerability is CVE-2025-20648 classified as?
CVE-2025-20648 is classified as an out of bounds read vulnerability.