CVE-2025-20774
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-20774 is a heap-based buffer overflow vulnerability in the display component of MediaTek chipsets running Android, caused by a missing bounds check that enables an out-of-bounds write. It affects devices running Android 14.0, 15.0, and 16.0 on a wide range of MediaTek SoCs including MT2718, MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6897, MT6899, MT6983, MT6985, MT6989, MT6991, MT8196, MT8676, MT8678, MT8792, and MT8793. The vulnerability was published on December 2, 2025, with a patch made available in MediaTek's December 2025 security bulletin (Patch ID: ALPS10196993; Issue ID: MSV-4796). It carries a CVSS v3.1 base score of 6.7 (Medium) (MediaTek Bulletin, Red Hat CVE).

Technical details

The root cause is a missing bounds check in the display driver component of MediaTek's Android firmware, classified as CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write). An attacker who has already obtained System-level privileges on the device can trigger the out-of-bounds write locally, potentially overwriting adjacent heap memory to escalate privileges further. No user interaction is required for exploitation. No public proof-of-concept or detailed technical write-up has been disclosed at this time (MediaTek Bulletin, Red Hat CVE).

Impact

Successful exploitation could allow an attacker who already holds System privileges to escalate to higher privilege levels on the affected Android device, with high impact to confidentiality, integrity, and availability. This could enable unauthorized access to sensitive system data, modification of system state, or disruption of device availability. The scope is limited to the local device (unchanged scope), but the breadth of affected MediaTek chipsets means a large number of Android devices across multiple OEMs could be at risk (MediaTek Bulletin).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept for CVE-2025-20774 at this time. The vulnerability requires the attacker to have already obtained System-level privileges on the device, significantly limiting the attack surface. The EPSS score is 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog (MediaTek Bulletin, Red Hat CVE).

Mitigation and workarounds

MediaTek has released a patch addressing this vulnerability in its December 2025 Product Security Bulletin (Patch ID: ALPS10196993). Users should apply the latest security updates provided by their device OEM (e.g., Lenovo has issued an advisory for affected MediaTek tablets). Recommended mitigations include applying the latest security patch, restricting and monitoring system-level access, implementing strict access controls, and regularly updating Android devices to the latest security version (MediaTek Bulletin, Lenovo Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • telegraf-1.38
NoYesSep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • flux-notification-controller
NoYesSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • thunderbird
NoYesSep 01, 2026
CVE-2026-84640HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management