CVE-2025-20763: High severity Google Android vulnerability
In mmdvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10267218; Issue ID: MSV-5032.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20763?
CVE-2025-20763 is classified as a critical vulnerability due to its potential for local escalation of privilege.
How do I fix CVE-2025-20763?
To mitigate CVE-2025-20763, apply the patch with ID ALPS10267218 as soon as it becomes available.
What causes CVE-2025-20763?
CVE-2025-20763 is caused by a missing bounds check leading to a possible out of bounds write in mmdvfs.
Who is affected by CVE-2025-20763?
CVE-2025-20763 affects specific versions of Google Android, particularly version 14.0 to 16.0.
Is user interaction required to exploit CVE-2025-20763?
No, user interaction is not needed for the exploitation of CVE-2025-20763.