Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9964 | In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09486425; Issue ID: MSV-2609. |
Fri, 18 Apr 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google android Mediatek Mediatek mt6765 Mediatek mt6768 Mediatek mt6781 Mediatek mt6789 Mediatek mt6833 Mediatek mt6853 Mediatek mt6877 Mediatek mt6885 Mediatek mt8768 Mediatek mt8771 Mediatek mt8781 Mediatek mt8786 Mediatek mt8791t |
|
| CPEs | cpe:2.3:h:mediatek:mt6765:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6768:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6781:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6789:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6885:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8771:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8786:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Google
Google android Mediatek Mediatek mt6765 Mediatek mt6768 Mediatek mt6781 Mediatek mt6789 Mediatek mt6833 Mediatek mt6853 Mediatek mt6877 Mediatek mt6885 Mediatek mt8768 Mediatek mt8771 Mediatek mt8781 Mediatek mt8786 Mediatek mt8791t |
Wed, 09 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 07 Apr 2025 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09486425; Issue ID: MSV-2609. | |
| Weaknesses | CWE-787 | |
| References |
|
Status: PUBLISHED
Assigner: MediaTek
Published:
Updated: 2026-02-26T18:28:55.285Z
Reserved: 2024-11-01T01:21:50.367Z
Link: CVE-2025-20657
Updated: 2025-04-07T13:55:38.022Z
Status : Analyzed
Published: 2025-04-07T04:15:19.577
Modified: 2025-04-18T16:11:52.513
Link: CVE-2025-20657
No data.
OpenCVE Enrichment
No data.
EUVD