CVE-2025-20656Exploit(google / android)

MEDIUMCVSS 6.8 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch google android systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09625423; Issue ID: MSV-3033.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android
  • mt6781
  • mt6789
  • mt6835

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
androidmt6781mt6789mt6835mt6855mt6878mt6879mt6886mt6895mt6897

9 versions affected across 20 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-01: 1PoC Mentioned / Linked · 2026-02-01: 1Exploit Tool / Code · 2026-02-01: 1Patch / Workaround · 2026-02-01: 1Technical Details · 2026-02-01: 102-01
Signal classification1 categories
Exploit
1100.0%
Full discourse1 post
  • Wh1teCoon@Wh1teCoon
    Exploit

    Beautiful heap overflow writeup on mediatek download agent. Chimera’s “secret sauce” was heapb8 - usb size mismatch letting you corrupt chunk headers for arbitrary write. works on dimensity 9400/8400, patched as CVE-2025-20656/20658. full chain in penumbra now #MediaTek #infosec

    Post summary

    A heap overflow in the Mediatek download agent allows arbitrary write; a full exploit chain exists in Penumbra, the vulnerability is patched under CVE‑2025‑20656/20658.

    10010105
    65 followersView on X
CPE platform detail24 entries

24 of 24 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid12.0--
OSgoogleandroid13.0--
OSgoogleandroid14.0--
OSgoogleandroid15.0--
Applinuxfoundationyocto4.0--
HWmediatekmt6781---
HWmediatekmt6789---
HWmediatekmt6835---
HWmediatekmt6855---
HWmediatekmt6878---
HWmediatekmt6879---
HWmediatekmt6886---
HWmediatekmt6895---
HWmediatekmt6897---
HWmediatekmt6983---
HWmediatekmt6985---
HWmediatekmt6989---
HWmediatekmt6990---
HWmediatekmt8196---
HWmediatekmt8370---
HWmediatekmt8390---
OSopenwrtopenwrt21.02.0--
OSopenwrtopenwrt23.05--
Apprdkcentralrdk-b2024q1--

Explore more