CVE-2025-21006: High severity Android libsavsvc vulnerability
Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21006?
CVE-2025-21006 is categorized as a high-severity vulnerability due to the potential for local attackers to exploit it for out-of-bounds memory writes.
How do I fix CVE-2025-21006?
To fix CVE-2025-21006, update libsavsvc to a version that is 15 or higher, which addresses the out-of-bounds write issue.
Who is affected by CVE-2025-21006?
CVE-2025-21006 affects devices running Android with libsavsvc versions prior to 15.
What are the consequences of CVE-2025-21006 if exploited?
Exploiting CVE-2025-21006 could allow local attackers to cause crashes, execute arbitrary code, or escalate privileges on affected devices.
Is there a workaround for CVE-2025-21006 while waiting for a patch?
Currently, the best workaround for CVE-2025-21006 is to limit access to affected devices and ensure they are updated as soon as patches are available.