CVE-2025-20802: Use After Free
Published Jan 6, 2026
·Updated
In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10238968; Issue ID: MSV-4914.
Affected Software
7 affected components
All of the following
Google Android=15.0
Any of the following
MediaTek Mt6991
MediaTek Mt8196
MediaTek Mt8367
MediaTek Mt8781
MediaTek Mt8786
MediaTek Mt8793
Event History
Jan 6, 2026
CVE Published
via MITRE·01:46 AM
Data Sourced
via MITRE·01:46 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20802?
CVE-2025-20802 has a high severity due to potential local escalation of privilege.
2
How do I fix CVE-2025-20802?
To fix CVE-2025-20802, apply the patch identified as ALPS10238968.
3
Who is affected by CVE-2025-20802?
CVE-2025-20802 affects Google Android version 15.0 running on certain MediaTek chipsets.
4
Is user interaction required to exploit CVE-2025-20802?
No, user interaction is not needed to exploit CVE-2025-20802.
5
What could be the consequence of exploiting CVE-2025-20802?
Exploiting CVE-2025-20802 could lead to local escalation of privilege for a malicious actor.