CVE-2025-20744: Use After Free
Published Nov 4, 2025
·Updated
In pda, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10127160; Issue ID: MSV-4542.
Affected Software
7 affected components
All of the following
Any of the following
Google Android=13.0
Google Android=14.0
Google Android=15.0
Google Android=16.0
Any of the following
MediaTek Mt6899
MediaTek Mt6991
MediaTek Mt8793
Event History
Nov 4, 2025
CVE Published
via MITRE·06:19 AM
Data Sourced
via MITRE·06:19 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20744?
CVE-2025-20744 has a high severity due to the potential for local escalation of privilege.
2
How do I fix CVE-2025-20744?
To fix CVE-2025-20744, apply the patch identified as ALPS10127160.
3
What software versions are affected by CVE-2025-20744?
CVE-2025-20744 affects Google Android versions 13.0, 14.0, 15.0, and 16.0.
4
Is user interaction needed to exploit CVE-2025-20744?
No, user interaction is not required for exploitation of CVE-2025-20744.
5
Who can exploit CVE-2025-20744?
A malicious actor who has already obtained System privilege can exploit CVE-2025-20744.