PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-20780 MediaTek, Inc. CVE debrief

CVE-2025-20780 is a high-severity vulnerability in the display component of Mediatek's products, potentially leading to local escalation of privilege. The vulnerability has a CVSS score of 7.8 and requires System privileges for exploitation, which can be obtained by a malicious actor. No user interaction is needed for exploitation. This vulnerability affects Mediatek-based devices, especially those with System privilege escalation vulnerabilities. Defenders and security teams should assess exposure and prioritize patching.

Vendor
MediaTek, Inc.
Product
MediaTek chipset
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-06
Original CVE updated
2026-09-30
Advisory published
2026-01-06
Advisory updated
2026-09-30

Who should care

Defenders and security teams responsible for Mediatek-based devices, especially those with System privilege escalation vulnerabilities, should assess exposure and prioritize patching.

Why it matters

CVE-2025-20780 is a high-severity vulnerability in Mediatek's display component, potentially leading to local escalation of privilege. Defenders and security teams should assess exposure and prioritize patching for devices with Mediatek components, especially those with System privilege escalation vulnerabilities.

  • Local escalation of privilege requires System privileges, which can be obtained by a malicious actor.
  • No user interaction is needed for exploitation, increasing the attack surface.
  • Successful exploitation could lead to unauthorized access and control of affected devices.
  • Patching and verification of Mediatek components are crucial to prevent potential attacks.

Technical summary

The CVE-2025-20780 vulnerability is caused by a use-after-free issue in the display component of Mediatek products. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The vulnerability affects Mediatek-based devices and defenders should assess exposure and prioritize patching for devices with Mediatek components, especially those with System privilege escalation vulnerabilities.

Defensive priority

Assess exposure and prioritize patching for devices with Mediatek components, especially those with System privilege escalation vulnerabilities.

Recommended defensive actions

  • Assess exposure of Mediatek-based devices to CVE-2025-20780
  • Prioritize patching for devices with System privilege escalation vulnerabilities
  • Verify patch availability and apply updates for affected Mediatek components
  • Monitor for potential exploitation attempts targeting CVE-2025-20780
  • Review and update incident response plans for local escalation of privilege vulnerabilities

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, including its description, CVSS score, and affected products. A vendor advisory is available from Mediatek. The vulnerability has been publicly disclosed and its details can be found in the CVE Program record and the NVD detail page. The Mediatek advisory provides additional information on the affected products and recommended actions.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-20780 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-20780

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-20780 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-20780

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.