CVE-2025-20655: Medium severity Google Android vulnerability
Published Apr 7, 2025
·Updated
In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: DTV04427687; Issue ID: MSV-3183.
Affected Software
4 affected components
All of the following
Any of the following
Google Android=12.0
Google Android=14.0
MediaTek Mt9972
Google Android
Event History
Apr 7, 2025
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
CVE Published
via MITRE·03:14 AM
Data Sourced
via MITRE·03:14 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-20655?
CVE-2025-20655 has been rated as potentially critical due to the risk of local information disclosure.
2
How do I fix CVE-2025-20655?
To fix CVE-2025-20655, apply the patch ID DTV04427687 provided by the software vendor.
3
What software is affected by CVE-2025-20655?
CVE-2025-20655 affects Android versions 12.0 and 14.0 as well as MediaTek MT9972.
4
Does CVE-2025-20655 require user interaction for exploitation?
No, CVE-2025-20655 can be exploited without any user interaction.
5
What kind of vulnerability is CVE-2025-20655?
CVE-2025-20655 is characterized as an out of bounds read vulnerability due to a missing bounds check.