CVE-2025-20797

7.8

MediaTek · Chipset (MT2718, MT6765, MT6768, MT6781, MT6833, MT6835, MT6853, MT6855)

A missing bounds check in the MediaTek battery driver leads to an out of bounds write, which can result in local privilege escalation.

Executive summary

A critical out of bounds write vulnerability in MediaTek chipsets allows a local attacker with system privileges to escalate their authority further, posing a significant risk to device integrity.

Vulnerability

The flaw is a stack-based buffer overflow (CWE-121) caused by a missing bounds check within the battery component. An attacker who has already obtained system-level access can leverage this vulnerability to gain further privileges without requiring user interaction.

Business impact

The potential for local privilege escalation represents a severe security risk, as it allows a compromised system to be fully controlled or manipulated by an attacker. Given the CVSS score of 7.8, this vulnerability is classified as High severity because it facilitates a complete compromise of system security controls, potentially leading to unauthorized data access or persistent malware installation.

Remediation

Immediate Action: Apply the specific security update provided by the device manufacturer or MediaTek using Patch ID ALPS10315812.

Proactive Monitoring: Monitor system logs for unexpected crashes or unauthorized attempts to access low-level hardware drivers.

Compensating Controls: Ensure that device security policies restrict unauthorized local access and maintain up-to-date kernel integrity protections to prevent the initial system-level compromise.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations utilizing devices equipped with the affected MediaTek chipsets must prioritize the deployment of the provided vendor patch. Although the exploit requires pre-existing system-level access, the ability to escalate privileges makes this a critical maintenance item for device security. Please verify the patch availability through your specific hardware vendor's security bulletin.

More MediaTek CVEs

Sources