Impact
In the Android modem component, a missing bounds check allows an out‑of‑bounds read, classified as CWE‑125. The read can be leveraged to execute arbitrary code on the device, enabling remote code execution without requiring higher privileges.
Affected Systems
The vulnerability affects the Android operating system supplied by Google, including all devices that include the modem firmware and its current builds. No specific affected versions are listed in the public disclosure, so all current releases should be considered potentially vulnerable until a vendor fix is published.
Risk and Exploitability
The flaw has a CVSS score of 7.8, indicating significant impact, while the EPSS probability is very low (<1%) and it is not listed in the CISA KEV catalog. Nevertheless, the attacker can trigger the issue remotely, with no user interaction required, implying that a network‑based adversary could compromise the device even without elevated privileges.
OpenCVE Enrichment