PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-20795 MediaTek, Inc. CVE debrief

A possible out of bounds write due to a missing bounds check in KeyInstall could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. This vulnerability is located in the KeyInstall component and its exploitation could lead to increased access to sensitive data, allowing malicious actors to execute arbitrary code, and potentially leading to lateral movement within the network. Android system administrators and security teams should assess exposure and apply patches if available.

Vendor
MediaTek, Inc.
Product
MediaTek chipset
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-06
Original CVE updated
2026-09-30
Advisory published
2026-01-06
Advisory updated
2026-09-30

Who should care

Android system administrators and security teams should assess exposure and apply patches if available. System owners with KeyInstall component in their Android systems should verify if System privilege has been obtained by malicious actors.

Why it matters

CVE-2025-20795 is a high-severity vulnerability in KeyInstall that could lead to local escalation of privilege. Android system administrators and security teams should assess exposure and apply patches if available.

  • Local escalation of privilege could lead to increased access to sensitive data
  • Successful exploitation could allow malicious actors to execute arbitrary code
  • System compromise could lead to lateral movement within the network
  • Patch application is necessary to prevent exploitation

Technical summary

The vulnerability is located in the KeyInstall component and is caused by a missing bounds check, which could lead to a possible out of bounds write. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. The vulnerability has a high CVSS score of 7.8 and is considered a high-severity issue. Android system administrators and security teams should assess exposure and apply patches if available to prevent exploitation and potential lateral movement within the network.

Defensive priority

Assess exposure and apply patch if available

Recommended defensive actions

  • Assess exposure of KeyInstall component in Android systems
  • Verify if System privilege has been obtained by malicious actors
  • Apply patch ALPS10276761 if available
  • Monitor for suspicious activity related to local escalation of privilege
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, including its description, CVSS score, and affected products. The vulnerability has been described as a high-severity issue in the KeyInstall component. There is no evidence of exploitation in the wild, but defenders should verify if System privilege has been obtained by malicious actors and monitor for suspicious activity related to local escalation of privilege.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-20795 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-20795

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-20795 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-20795

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.