Impact
The vulnerability stems from a use‑after‑free bug in the Zircon kernel pager proxy used by Android. When triggered, an attacker could overwrite freed memory to execute code with kernel privileges, leading to a privilege escalation from userspace to kernel space. The weakness corresponds to CWE‑416, a common memory corruption flaw that can be leveraged for elevated privileges.
Affected Systems
The flaw affects devices running Google Android. No specific version details or product variants are listed in the advisory, so any device using the affected Zircon kernel component may be vulnerable until updated.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the description does not specify remote or local attack requirements, the attack vector is inferred to be local, requiring the attacker to run malicious code from a compromised app or process. Although an exploitation technique is not detailed, the combination of a use‑after‑free in the kernel and the ability to gain kernel privileges makes the risk severe; the CVSS score of 8.8 indicates a high potential impact.
OpenCVE Enrichment