Impact
isCallerAllowed in WalletContextualLocationsService.kt lacks a permission check, permitting an attacker to retrieve wallet data on the device. The flaw does not require elevated privileges or user interaction, enabling straightforward local data extraction. The exposed information could reveal sensitive transaction or payment details, compromising confidentiality. This weakness corresponds to missing authorization (CWE-862).
Affected Systems
Google Android devices are affected, although specific product versions or release numbers are not provided in the advisory.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a very low likelihood of exploitation. The CVSS score of 3.3 labels the flaw as low severity. However, the missing permission check enables any local user to retrieve wallet data without additional privileges or user interaction, resulting in local information disclosure.
OpenCVE Enrichment