Impact
The vulnerability arises from an integer overflow in multiple functions of ubsan_throwing_runtime.cpp, potentially causing an UBSan failure. This flaw can be triggered remotely and results in a denial-of-service condition without requiring elevated privileges or user interaction. The impact is an interruption of services that rely on the affected functions, affecting the availability of the system.
Affected Systems
The affected product is Google Android. No specific version information is provided, so all currently supported Android releases that include the vulnerable UBSan implementation are potentially impacted until a patch is applied.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that publicly known exploitation data is scarce. Nevertheless, the nature of the flaw grants remote attackers the ability to crash the system, which is a moderate severity outcome with a CVSS score of 6.5. The lack of required privileges and user interaction lowers the barrier to exploitation, suggesting that the risk remains significant while a vendor fix is pending.
OpenCVE Enrichment