CVE-2025-20721: High severity MediaTek Iot Yocto vulnerability
In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10089545; Issue ID: MSV-4279.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20721?
CVE-2025-20721 is classified as a potentially high severity vulnerability due to the risk of local privilege escalation.
How do I fix CVE-2025-20721?
To mitigate CVE-2025-20721, apply the security patch identified as ALPS10089545.
Who is affected by CVE-2025-20721?
Devices running MediaTek IoT Yocto 25.0 and Google Android versions 13.0 to 16.0 are affected by CVE-2025-20721.
What type of vulnerability is CVE-2025-20721?
CVE-2025-20721 is an out of bounds write vulnerability due to a missing bounds check in imgsensor.
Is user interaction required to exploit CVE-2025-20721?
No, user interaction is not needed for the exploitation of CVE-2025-20721.