Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13329 | In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09698599; Issue ID: MSV-3228. |
| Link | Providers |
|---|---|
| https://corp.mediatek.com/product-security-bulletin/May-2025 |
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 07 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Tue, 06 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google android Mediatek Mediatek mt2718 Mediatek mt6878 Mediatek mt6897 Mediatek mt6899 Mediatek mt6989 Mediatek mt6991 Mediatek mt8196 Mediatek mt8391 Mediatek mt8676 Mediatek mt8678 |
|
| CPEs | cpe:2.3:h:mediatek:mt2718:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6878:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6897:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6899:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6989:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6991:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8196:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8391:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8676:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Google
Google android Mediatek Mediatek mt2718 Mediatek mt6878 Mediatek mt6897 Mediatek mt6899 Mediatek mt6989 Mediatek mt6991 Mediatek mt8196 Mediatek mt8391 Mediatek mt8676 Mediatek mt8678 |
|
| Metrics |
cvssV3_1
|
Mon, 05 May 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09698599; Issue ID: MSV-3228. | |
| Weaknesses | CWE-787 | |
| References |
|
Status: PUBLISHED
Assigner: MediaTek
Published:
Updated: 2026-02-26T18:29:04.153Z
Reserved: 2024-11-01T01:21:50.370Z
Link: CVE-2025-20671
Updated: 2025-05-07T14:58:31.813Z
Status : Modified
Published: 2025-05-05T03:15:22.420
Modified: 2025-05-07T15:15:56.947
Link: CVE-2025-20671
No data.
OpenCVE Enrichment
No data.
EUVD