Impact
The vulnerability arises from a missing bounds check that permits an out‑of‑bounds write in the Android operating system, allowing an attacker to acquire higher privileges on the device without needing any additional execution rights. Because the flaw does not require user interaction, a local attacker with basic device access can exploit it to gain elevated privileges and potentially control protected system resources. This can lead to complete system takeover if leveraged further.
Affected Systems
All Google Android operating system builds may be affected; the vulnerability is not limited to a specific product version or family, but no version information is provided in the available data.
Risk and Exploitability
The CVSS score of 10.0 signals maximum severity, indicating that exploitation would provide full privilege escalation. The EPSS score of less than 1% suggests that, as of now, there is a low probability of widespread exploitation, although the lack of user interaction requirement increases the risk to any device with local access. The vulnerability is not listed in CISA’s KEV catalog, but its high severity warrants careful monitoring and timely remediation.
OpenCVE Enrichment