Impact
In the recovery_ui.cpp component, the PostWipeData routine contains a logic error that prevents complete erasure of data during a factory reset. This flaw allows an attacker who can access the device locally to read residual information that should have been cleared, delivering confidential data disclosure. The attack requires no additional execution privileges and does not need user interaction, meaning an adversary can trigger it simply by performing a factory reset on the compromised device.
Affected Systems
Devices running Google Android, particularly those that include the recovery_ui component referenced in Google’s Pixel security bulletin. No explicit version range is provided, so any Android build that contains the vulnerable code may be affected.
Risk and Exploitability
The CVSS score of 4.0 denotes a low severity rating, and the EPSS score of less than 1% indicates a low likelihood of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no large‑scale incidents have been reported. Nevertheless, because the flaw can be triggered without elevated privileges, any compromised device could leak private data during a factory reset.
OpenCVE Enrichment