CVE-2025-20795

7.8

MediaTek · Chipset (MT2718, MT6580, MT6739, MT6761, MT6765, MT6768, MT6779, MT6781)

A missing bounds check in the MediaTek KeyInstall component allows for an out of bounds write, potentially leading to local privilege escalation.

Executive summary

A critical out of bounds write vulnerability in MediaTek chipsets enables local attackers with existing system-level access to escalate their privileges.

Vulnerability

The flaw is an out of bounds write (CWE-787) within the KeyInstall function. Exploitation requires the attacker to have already obtained System level privileges, at which point they can trigger the vulnerability without user interaction.

Business impact

Successful exploitation of this vulnerability allows a malicious actor to gain elevated system permissions, potentially leading to total compromise of the affected device. Given the CVSS score of 7.8, this poses a significant risk to data integrity and system availability, particularly in mobile or embedded environments where unauthorized privilege escalation facilitates deeper persistent access.

Remediation

Immediate Action: Apply the vendor-provided security update identified by Patch ID ALPS10276761 as listed in the January 2026 MediaTek security bulletin.

Proactive Monitoring: Monitor system logs for unusual crash patterns or unexpected behavior in the KeyInstall process that may indicate failed exploitation attempts.

Compensating Controls: Ensure that existing security policies restrict low-privileged access to the system, as the exploit requires an initial foothold with system-level permissions to succeed.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

This vulnerability highlights the importance of maintaining up-to-date firmware on all MediaTek-based hardware. Administrators should prioritize the deployment of the January 2026 security patch to mitigate the risk of local privilege escalation and ensure that system-level access remains protected from secondary exploitation vectors.

More MediaTek CVEs

Sources