In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09456673; Issue ID: MSV-2584.
Metrics
Affected Vendors & Products
References
History
Tue, 22 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android Mediatek Mediatek mt2718 Mediatek mt6879 Mediatek mt6989 Mediatek mt8196 Mediatek mt8370 Mediatek mt8390 Mediatek mt8395 Mediatek mt8673 Mediatek mt8678 |
|
CPEs | cpe:2.3:h:mediatek:mt2718:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6989:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8196:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8370:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8390:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Google
Google android Mediatek Mediatek mt2718 Mediatek mt6879 Mediatek mt6989 Mediatek mt8196 Mediatek mt8370 Mediatek mt8390 Mediatek mt8395 Mediatek mt8673 Mediatek mt8678 |
Tue, 04 Mar 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 03 Mar 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09456673; Issue ID: MSV-2584. | |
Weaknesses | CWE-125 | |
References |
|

Status: PUBLISHED
Assigner: MediaTek
Published:
Updated: 2025-03-04T16:16:45.516Z
Reserved: 2024-11-01T01:21:50.366Z
Link: CVE-2025-20648

Updated: 2025-03-04T16:16:35.260Z

Status : Analyzed
Published: 2025-03-03T03:15:09.620
Modified: 2025-04-22T13:46:59.780
Link: CVE-2025-20648

No data.