CVE-2025-20655

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 7, 2025
Updated: Apr 9, 2025
CWE ID 125

Summary

CVE-2025-20655 is a vulnerability affecting the keymaster component that allows for a possible out-of-bounds read due to a missing bounds check. This issue could result in local information disclosure if an attacker has previously gained the System privilege, requiring no user interaction for exploitation. The vulnerability, identified as MSV-3183, has been addressed through the patch ID DTV04427687.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share