CVE-2025-20730
published 2025-11-04CVE-2025-20730: In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a malicious…
PriorityP429medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.07%
0.1th percentile
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10068463; Issue ID: MSV-4141.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| linuxfoundation | yocto | — | — |
| openwrt | openwrt | — | — |
| openwrt | openwrt | — | — |
| rdkcentral | rdk-b | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ghx5-r834-wpjq: In preloader, there is a possible escalation of privilege due to an insecure default value
ghsa_unreviewed·2025-11-04
CVE-2025-20730 [MEDIUM] CWE-287 GHSA-ghx5-r834-wpjq: In preloader, there is a possible escalation of privilege due to an insecure default value
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10068463; Issue ID: MSV-4141.
Android
CVE-2025-20730: preloader
vendor_android·2025-12-01·CVSS 6.7
CVE-2025-20730 [MEDIUM] CVE-2025-20730: preloader
Android Security Bulletin 2025-12-01
CVE: CVE-2025-20730
Severity: HIGH
Component: preloader
References: A-442288321M-ALPS10068463*
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-04
Published