CVE-2025-20797: High severity Google Android vulnerability
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID: MSV-5534.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20797?
CVE-2025-20797 is considered a high severity vulnerability due to the potential for local escalation of privilege.
How do I fix CVE-2025-20797?
To address CVE-2025-20797, users should apply the patch identified as ALPS10315812.
What causes CVE-2025-20797?
CVE-2025-20797 is caused by a missing bounds check in the battery component.
Who is affected by CVE-2025-20797?
CVE-2025-20797 affects devices running Google Android versions 14.0, 15.0, and 16.0.
Can CVE-2025-20797 be exploited without user interaction?
Yes, CVE-2025-20797 can be exploited without user interaction if the attacker has obtained System privileges.