CVE-2025-20661 Details
Description
In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: DTV04436357; Issue ID: MSV-3185.
A vulnerability in the PlayReady Trusted Application (TA) component of MediaTek chipsets, specifically in the MT9972 chipset, has been identified. This vulnerability arises from a missing bounds check, which creates a potential out-of-bounds read condition. If exploited, it could lead to local escalation of privileges, but requires that the attacker has already obtained System privileges. The vulnerability is present in certain versions of the software running on Android 12.0 and 14.0.
MediaTek has issued a patch for this vulnerability, which can be applied by device manufacturers. Instructions for applying the patch are available through MediaTek's official channels.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://corp.mediatek.com/product-security-bulletin/April-2025 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| google android | 12.0 - 14.0 |
CPE
Remediation
| |
| mediatek mt9972 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2025 | Initial Analysis | [email protected] |
| Apr 7, 2025 | CVE Modified | CISA-ADP |
| Apr 7, 2025 | New CVE Received | [email protected] |