CVE-2025-20797
7.8MediaTek · Chipset (MT2718, MT6765, MT6768, MT6781, MT6833, MT6835, MT6853, MT6855)
A missing bounds check in the MediaTek battery driver leads to an out of bounds write, which can result in local privilege escalation.
Executive summary
A critical out of bounds write vulnerability in MediaTek chipsets allows a local attacker with system privileges to escalate their authority further, posing a significant risk to device integrity.
Vulnerability
The flaw is a stack-based buffer overflow (CWE-121) caused by a missing bounds check within the battery component. An attacker who has already obtained system-level access can leverage this vulnerability to gain further privileges without requiring user interaction.
Business impact
The potential for local privilege escalation represents a severe security risk, as it allows a compromised system to be fully controlled or manipulated by an attacker. Given the CVSS score of 7.8, this vulnerability is classified as High severity because it facilitates a complete compromise of system security controls, potentially leading to unauthorized data access or persistent malware installation.
Remediation
Immediate Action: Apply the specific security update provided by the device manufacturer or MediaTek using Patch ID ALPS10315812.
Proactive Monitoring: Monitor system logs for unexpected crashes or unauthorized attempts to access low-level hardware drivers.
Compensating Controls: Ensure that device security policies restrict unauthorized local access and maintain up-to-date kernel integrity protections to prevent the initial system-level compromise.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing devices equipped with the affected MediaTek chipsets must prioritize the deployment of the provided vendor patch. Although the exploit requires pre-existing system-level access, the ability to escalate privileges makes this a critical maintenance item for device security. Please verify the patch availability through your specific hardware vendor's security bulletin.