CVE-2025-20668: High severity Google Android vulnerability
In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09625562; Issue ID: MSV-3027.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20668?
CVE-2025-20668 has a severity level that can lead to local escalation of privilege due to an out of bounds write.
How do I fix CVE-2025-20668?
To fix CVE-2025-20668, apply the patch identified as ALPS09625562.
Who is affected by CVE-2025-20668?
CVE-2025-20668 affects specific versions of Android 14.0 and 15.0.
Can CVE-2025-20668 be exploited without user interaction?
Yes, CVE-2025-20668 can be exploited without user interaction since it requires only that a malicious actor has obtained system privilege.
What are the potential impacts of CVE-2025-20668?
The potential impact of CVE-2025-20668 includes local escalation of privilege, which can compromise the security of the affected system.