CVE-2025-20636
published 2025-02-03CVE-2025-20636: In secmem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has…
PriorityP427medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.08%
0.2th percentile
In secmem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09403554; Issue ID: MSV-2431.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-78fc-cgpq-9vq9: In secmem, there is a possible out of bounds write due to a missing bounds check
ghsa_unreviewed·2025-02-03
CVE-2025-20636 [HIGH] CWE-787 GHSA-78fc-cgpq-9vq9: In secmem, there is a possible out of bounds write due to a missing bounds check
In secmem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09403554; Issue ID: MSV-2431.
Android
CVE-2025-20636: secmem
vendor_android·2025-02-01·CVSS 6.7
CVE-2025-20636 [MEDIUM] CVE-2025-20636: secmem
Android Security Bulletin 2025-02-01
CVE: CVE-2025-20636
Severity: HIGH
Component: secmem
References: A-381773171
M-ALPS09403554
*
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-03
Published