Impact
A logic error in several code paths can result in an out‑of‑bounds write. This flaw can be exploited to execute arbitrary code with the privileges of the vulnerable process, and it does not require elevated rights or special privileges. The vulnerability is operable without user interaction, meaning an attacker can trigger crafted data or commands.
Affected Systems
The vulnerability affects Google Android. No specific OS versions or device models are identified in the available data, so all Android installations that contain the affected code are potentially at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates a high likelihood of serious impact. The EPSS score is 0.00284, and the vulnerability is not listed in CISA's KEV catalog, so no public exploits are formally documented. User interaction is not required, so the attack vector is inferred to be remote. An attacker could exploit the flaw from a network or an application that can supply the required payload without the user’s knowledge.
OpenCVE Enrichment