Impact
A confused deputy flaw in Android’s FaceEnroll.kt can cause local users to gain higher privileges without requiring additional code execution or user interaction. The vulnerability, classified as CWE‑441, allows attackers to elevate privileges locally.
Affected Systems
The flaw affects devices running Google Android version 16.0.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity, but the EPSS score of less than 1 % suggests a low probability of exploitation at this time. The issue is not listed in the CISA KEV catalog. Exploitation requires local access and does not need user interaction, implying that any local user could potentially trigger the privilege escalation if the device remains unpatched.
OpenCVE Enrichment