CVE-2025-20766: Input Validation
In display, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4820.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20766?
The severity of CVE-2025-20766 is considered potentially critical due to its ability to enable local escalation of privilege.
How do I fix CVE-2025-20766?
You can fix CVE-2025-20766 by applying the patch ID ALPS10196993 as soon as it is available for your affected device.
Who is affected by CVE-2025-20766?
CVE-2025-20766 affects devices running Google Android versions 14.0, 15.0, and 16.0.
Can CVE-2025-20766 be exploited without user interaction?
Yes, CVE-2025-20766 can be exploited without user interaction if a malicious actor has obtained System privilege.
What type of vulnerability is CVE-2025-20766 classified as?
CVE-2025-20766 is classified as a memory corruption vulnerability due to improper input validation in the display component.