CVE-2025-20658: Medium severity Google Android vulnerability
In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09474894; Issue ID: MSV-2597.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20658?
CVE-2025-20658 is classified as a moderate severity vulnerability due to potential privilege escalation risks.
How do I fix CVE-2025-20658?
To resolve CVE-2025-20658, apply the latest patch identified as ALPS09474894 provided by the vendor.
What causes CVE-2025-20658?
CVE-2025-20658 is caused by a logic error that allows for a permission bypass.
Who is affected by CVE-2025-20658?
CVE-2025-20658 affects devices running specific versions of Android and various MediaTek chipsets.
Is user interaction required for exploiting CVE-2025-20658?
No, user interaction is not required for exploiting CVE-2025-20658, making it a higher risk issue.