Skip to main content
EPSS 0.1%top 100%

CVE-2025-20804: CWE-416 Use After Free in MediaTek, Inc. MediaTek chipset

0
Medium
VulnerabilityCVE-2025-20804cvecve-2025-20804cwe-416
Published: 01/06/2026 (01/06/2026, 01:47:12 UTC)
Source: CVE Database V5
Vendor/Project: MediaTek, Inc.
Product: MediaTek chipset

Description

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10198951; Issue ID: MSV-4503.

CVSS v3.1

Score 6.7medium

Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected software

MediaTek, Inc.

MediaTek chipset

Affected versions
=MT6899=MT6991

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 03/30/2026, 19:28:12 UTC

Technical Analysis

CVE-2025-20804 is a use-after-free vulnerability classified under CWE-416 affecting MediaTek chipsets MT6899 and MT6991. The flaw exists within the dpe component, where memory is freed prematurely but subsequently accessed, causing memory corruption. This corruption can be leveraged by an attacker who already has System-level privileges on the device to escalate their privileges further, potentially gaining higher control or bypassing security mechanisms. Exploitation requires local access and user interaction, which limits remote exploitation but still poses a significant risk in scenarios where an attacker has partial control or presence on the device. The vulnerability impacts confidentiality, integrity, and availability due to the potential for arbitrary code execution or system instability. The CVSS 3.1 base score is 6.7, reflecting a medium severity with low attack vector (local), low attack complexity, high privileges required, and no user interaction needed for the privilege escalation step itself. The vulnerability was published in early 2026, with no known exploits in the wild at this time. MediaTek has assigned patch ID ALPS10198951 to address this issue. The vulnerability highlights the importance of secure memory management in chipset firmware and drivers, especially in components like dpe that handle critical system functions.

Potential Impact

The primary impact of CVE-2025-20804 is local privilege escalation on devices using affected MediaTek chipsets, which can lead to unauthorized access to sensitive system functions and data. This can compromise the confidentiality and integrity of the system by allowing attackers to execute arbitrary code with elevated privileges or disrupt system availability through memory corruption. Although exploitation requires prior System-level access and user interaction, it can be used as a stepping stone in multi-stage attacks to fully compromise a device. This is particularly concerning for mobile devices, IoT devices, and embedded systems relying on these chipsets, potentially affecting user data, device stability, and security controls. Organizations deploying these chipsets in consumer electronics, telecommunications infrastructure, or industrial systems face risks of targeted attacks or insider threats leveraging this vulnerability to deepen their control over affected devices.

Mitigation Recommendations

To mitigate CVE-2025-20804, organizations should promptly apply the official patch ALPS10198951 provided by MediaTek or their device manufacturers. Since exploitation requires local System privileges and user interaction, enforcing strict access controls and minimizing privileged user accounts can reduce risk. Employing endpoint protection solutions that monitor for unusual privilege escalation attempts and memory corruption behaviors can provide additional defense. Regularly updating device firmware and drivers ensures vulnerabilities are addressed timely. For environments with high security requirements, consider implementing runtime memory protection mechanisms such as Control Flow Integrity (CFI) and Address Space Layout Randomization (ASLR) if supported by the chipset. Conduct thorough security audits on devices using these chipsets to detect any signs of compromise. Finally, educate users about the risks of interacting with untrusted software or content that could trigger the vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
MediaTek
Date Reserved
2024-11-01T01:21:50.407Z
State
PUBLISHED

Threat ID: 695c6e7a3839e44175bdd40d

Added to database: 01/06/2026, 02:07:54 UTC

Last enriched: 03/30/2026, 19:28:12 UTC

Last updated: 09/10/2026, 22:30:01 UTC

Views: 136

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses