CVE-2025-20768: High severity Google Android vulnerability
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4805.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20768?
CVE-2025-20768 is considered a moderate severity vulnerability due to the potential for local escalation of privilege.
How do I fix CVE-2025-20768?
To fix CVE-2025-20768, apply the patch with ID ALPS10196993 promptly.
Who is affected by CVE-2025-20768?
CVE-2025-20768 affects users of Google Android versions 14.0, 15.0, and 16.0.
Can CVE-2025-20768 be exploited without user interaction?
Yes, CVE-2025-20768 can be exploited without user interaction, requiring only that the attacker has system privileges.
What are the potential consequences of CVE-2025-20768?
The consequences of CVE-2025-20768 include possible local escalation of privilege, allowing an attacker to gain unauthorized access to sensitive resources.