CVE-2025-20979: High severity Android libsavscmn vulnerability
Published May 7, 2025
·Updated
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.
Affected Software
2 affected components
Android libsavscmn<15
Google Android<15.0
Event History
May 7, 2025
CVE Published
via MITRE·08:24 AM
Data Sourced
via MITRE·08:24 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20979?
CVE-2025-20979 is classified as a critical severity vulnerability due to its potential to allow local attackers to execute arbitrary code.
2
How do I fix CVE-2025-20979?
To mitigate CVE-2025-20979, update to libsavscmn version 15 or later as this version addresses the vulnerability.
3
Who is affected by CVE-2025-20979?
CVE-2025-20979 affects users of libsavscmn on Android platforms prior to version 15.
4
What type of vulnerability is CVE-2025-20979?
CVE-2025-20979 is an out-of-bounds write vulnerability that can lead to arbitrary code execution.
5
Can CVE-2025-20979 be exploited remotely?
CVE-2025-20979 requires local access, meaning it cannot be exploited remotely and needs a local attacker to execute.