MediaTek Issues Security Update to Patch Multiple Chipset Flaws
## Cybersecurity: MediaTek September 2025 Product Security Bulletin
Cybersecurity: MediaTek September 2025 Product Security Bulletin
On Fri, Sep 1, 2025, MediaTek released its September 2025 Product Security Bulletin, detailing the disclosure and remediation of critical and moderate vulnerabilities within its modem and system components.
The bulletin indicates that three high-severity vulnerabilities and three medium-severity vulnerabilities were identified, assessed using the Common Vulnerability Scoring System version 3.1 (CVSS v3.1). These vulnerabilities may allow remote or local privilege escalation and denial-of-service conditions on MediaTek-based devices.
CVE Identifier Title Severity Exploitation Impact
CVE-2025-20708 Out-of-bounds write in Modem High Remote privilege escalation via rogue base station
CVE-2025-20703 Out-of-bounds read in Modem High Remote denial of service via rogue base station
CVE-2025-20704 Out-of-bounds write in Modem High Remote privilege escalation via rogue base station
These vulnerabilities may allow remote or local privilege escalation and denial-of-service conditions on MediaTek-based devices.
CVE-2025-20705 Use after free in monitor_hang Medium Local privilege escalation with System privilege
CVE-2025-20706 Use after free in mbrain Medium Local privilege escalation with System privilege
CVE-2025-20707 Use after free in geniezone Medium Local privilege escalation with System privilege
CVE-2025-20708: An out-of-bounds write in the modem subsystem could allow remote escalation of privilege if a device connects to a rogue base station. Affects over 70 chipset models, including MT6853, MT6877, MT6899, MT6980, and MT8893, with modem firmware NR15 through NR17R. CVE-2025-20703: An out-of-bounds read in the modem subsystem that could lead to remote denial of service under similar conditions, affecting similar chipset models and firmware versions. CVE-2025-20704: A second out-of-bounds write in modem firmware NR17/NR17R that also enables remote privilege escalation, impacting chipsets like MT6835T, MT6878M, and MT8883.
Three medium-severity use-after-free vulnerabilities in system components were also detailed:
CVE-2025-20705: In the monitor_hang driver, could permit local privilege escalation on devices running Android 13.0 through 16.0, OpenWRT 19.07/21.02, or Yocto 2.6. Affected chipsets include MT6765, MT6789, MT8169, and others. CVE-2025-20706: In the mbrain component, impacts Android 14.0 and 15.0 on chipsets such as MT6989 and MT8678. CVE-2025-20707: In the geniezone module, affects Android 13.0 to 15.0 on chipsets including MT6853, MT8792, and MT8883.
MediaTek has issued patches for all identified vulnerabilities to device OEMs, who are advised to incorporate these updates into firmware releases. The company assures that proactive measures were taken before public disclosure to ensure security.
For further information or to report new vulnerabilities, stakeholders are encouraged to visit MediaTek’s Report Security Vulnerability page on their corporate website.
Based on reporting by GBHackers.
