Impact
Improper input validation in several Android image handling components allows a local user to read images belonging to other users, which in turn can lead to a local privilege escalation without requiring any additional execution rights. The flaw can expose private image data and, because it bypasses normal access controls, it may enable the attacker to gain higher privileges on the device. User interaction is needed for exploitation. The vulnerability corresponds to CWE‑20, highlighting improper input validation.
Affected Systems
Google’s Android operating system is affected, specifically builds 14.0, 15.0, 16.0, and the 16.0 qpr2_beta series (qpr2_beta_1, qpr2_beta_2, qpr2_beta_3). Any device running these builds is at risk if the vulnerability remains unpatched.
Risk and Exploitability
The CVSS score of 7.8 signals high severity, while the EPSS score of < 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation. Exploitation can occur only after a user has interacted with a malicious image or app, so it is a local privilege escalation and information disclosure issue that requires local user action.
OpenCVE Enrichment