Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

MediaTek Issues Security Update to Patch Multiple Chipset Flaws

## Cybersecurity: MediaTek September 2025 Product Security Bulletin

Cybersecurity: MediaTek September 2025 Product Security Bulletin

On Fri, Sep 1, 2025, MediaTek released its September 2025 Product Security Bulletin, detailing the disclosure and remediation of critical and moderate vulnerabilities within its modem and system components.

The bulletin indicates that three high-severity vulnerabilities and three medium-severity vulnerabilities were identified, assessed using the Common Vulnerability Scoring System version 3.1 (CVSS v3.1). These vulnerabilities may allow remote or local privilege escalation and denial-of-service conditions on MediaTek-based devices.

CVE Identifier Title Severity Exploitation Impact

CVE-2025-20708 Out-of-bounds write in Modem High Remote privilege escalation via rogue base station

CVE-2025-20703 Out-of-bounds read in Modem High Remote denial of service via rogue base station

CVE-2025-20704 Out-of-bounds write in Modem High Remote privilege escalation via rogue base station

These vulnerabilities may allow remote or local privilege escalation and denial-of-service conditions on MediaTek-based devices.
Julia Kramer · Thehackingpost

CVE-2025-20705 Use after free in monitor_hang Medium Local privilege escalation with System privilege

CVE-2025-20706 Use after free in mbrain Medium Local privilege escalation with System privilege

CVE-2025-20707 Use after free in geniezone Medium Local privilege escalation with System privilege

CVE-2025-20708: An out-of-bounds write in the modem subsystem could allow remote escalation of privilege if a device connects to a rogue base station. Affects over 70 chipset models, including MT6853, MT6877, MT6899, MT6980, and MT8893, with modem firmware NR15 through NR17R. CVE-2025-20703: An out-of-bounds read in the modem subsystem that could lead to remote denial of service under similar conditions, affecting similar chipset models and firmware versions. CVE-2025-20704: A second out-of-bounds write in modem firmware NR17/NR17R that also enables remote privilege escalation, impacting chipsets like MT6835T, MT6878M, and MT8883.

Advertisement

Three medium-severity use-after-free vulnerabilities in system components were also detailed:

CVE-2025-20705: In the monitor_hang driver, could permit local privilege escalation on devices running Android 13.0 through 16.0, OpenWRT 19.07/21.02, or Yocto 2.6. Affected chipsets include MT6765, MT6789, MT8169, and others. CVE-2025-20706: In the mbrain component, impacts Android 14.0 and 15.0 on chipsets such as MT6989 and MT8678. CVE-2025-20707: In the geniezone module, affects Android 13.0 to 15.0 on chipsets including MT6853, MT8792, and MT8883.

MediaTek has issued patches for all identified vulnerabilities to device OEMs, who are advised to incorporate these updates into firmware releases. The company assures that proactive measures were taken before public disclosure to ensure security.

For further information or to report new vulnerabilities, stakeholders are encouraged to visit MediaTek’s Report Security Vulnerability page on their corporate website.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories