
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20801 is a memory corruption vulnerability in the MediaTek seninf (sensor interface) component caused by a race condition, which can lead to local escalation of privilege. It affects Android versions 13.0, 14.0, 15.0, and 16.0 running on MediaTek chipsets MT6878, MT6897, MT6899, MT6985, MT6989, MT6991, MT6993, MT8792, MT8796, and MT8798. The vulnerability was published on January 5–6, 2026, and a patch was made available via MediaTek's January 2026 Product Security Bulletin. It carries a CVSS v3.1 base score of 7.0 (High) (MediaTek Advisory, Red Hat CVE).
The vulnerability is rooted in improper synchronization when accessing shared resources within the seninf kernel driver module (CWE-362: Race Condition; CWE-415: Double Free). When concurrent execution paths access the same shared resource without adequate locking, a double-free condition can be triggered, resulting in memory corruption. Exploitation requires that the attacker already holds System-level privileges on the device, and no user interaction is needed. The patch is identified as ALPS10251210 (Issue ID: MSV-4926) (MediaTek Advisory).
Successful exploitation allows a local attacker with existing System privileges to escalate further, achieving high impact on confidentiality, integrity, and availability of the affected device. The memory corruption resulting from the double-free condition could enable arbitrary code execution at a higher privilege level within the kernel context. This could facilitate deeper device compromise, persistent access, or bypassing of security boundaries on affected Android devices (MediaTek Advisory, Red Hat CVE).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for the attacker to already possess System-level privileges on the target device, significantly limiting the attack surface (MediaTek Advisory).
MediaTek has released a patch (Patch ID: ALPS10251210) addressed in the January 2026 Product Security Bulletin. Device manufacturers and OEMs should integrate and distribute this patch to affected devices running Android 13.0, 14.0, 15.0, and 16.0 on the affected chipsets. Lenovo has also published a vendor advisory for affected MediaTek-based tablets. As an interim measure, restrict System-level privilege access to trusted applications only and monitor for anomalous system-level process behavior (MediaTek Advisory, Lenovo Advisory).
The vulnerability received standard coverage from vulnerability tracking platforms and security aggregators following MediaTek's January 2026 bulletin. Lenovo issued a dedicated advisory for affected MediaTek-based tablet products. No notable researcher commentary or significant social media discussion has been identified beyond routine vulnerability database entries (Lenovo Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."