CVE-2025-20657
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Published Apr 7, 2025
Updated: Apr 18, 2025
CWE ID 787
Summary
CVE-2025-20657 is a vulnerability affecting the vdec component, where improper input validation allows for a permission bypass. This issue could potentially enable local privilege escalation for an attacker who has already obtained System privileges. User interaction is not needed for exploitation. The patch ID for mitigation is ALPS09486425, and the issue has been identified as MSV-2609.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Android