
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20775 is a use-after-free memory corruption vulnerability in the display component of MediaTek-powered Android devices. It was published on December 2, 2025, and addressed in MediaTek's December 2025 Product Security Bulletin (Patch ID: ALPS10182914; Issue ID: MSV-4795). The vulnerability affects Android 14.0, 15.0, and 16.0 running on a wide range of MediaTek chipsets including MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6897, MT6899, MT6983, MT6985, MT6989, MT6991, and numerous MT8xxx series chips. It carries a CVSS v3.1 base score of 6.7 (Medium) (MediaTek Bulletin, Red Hat CVE).
The vulnerability is classified under CWE-416 (Use After Free) and CWE-415 (Double Free), rooted in improper memory management within the Android display subsystem on MediaTek chipsets. An attacker who has already obtained System-level privileges can trigger memory corruption by accessing freed memory in the display component, potentially redirecting execution flow to attacker-controlled code. The attack vector is local, requires high privileges (System), and no user interaction is needed. No public technical write-up or proof-of-concept code has been identified at this time (MediaTek Bulletin).
Successful exploitation allows a local attacker with System privilege to escalate privileges further, potentially achieving full device compromise. The vulnerability carries high confidentiality, integrity, and availability impacts — meaning an attacker could access sensitive data, manipulate system state, and disrupt device operation. Given the breadth of affected MediaTek chipsets across Android 14–16, a large number of consumer and enterprise Android devices are within scope (MediaTek Bulletin, Red Hat CVE).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018%, reflecting a very low probability of exploitation in the near term. Exploitation is constrained by the requirement for the attacker to already possess System-level privileges on the target device (MediaTek Bulletin).
MediaTek has released a patch addressing this vulnerability in its December 2025 Product Security Bulletin (Patch ID: ALPS10182914). Device manufacturers and OEMs should integrate and distribute this patch to affected devices running Android 14.0, 15.0, and 16.0 with the listed MediaTek chipsets. Lenovo has also published a corresponding advisory for affected MediaTek-based tablets (Lenovo Advisory). As interim mitigations, organizations should restrict System-level access, enforce robust access controls, and monitor for anomalous local privilege escalation activity on affected devices (MediaTek Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."