Impact
A missing permission check in the Android bootloader can be exploited to elevate an attacker’s privileges from a regular application to the system level, granting full control over the device. The vulnerability allows local privilege escalation without requiring any user interaction, enabling arbitrary code execution with system execution rights.
Affected Systems
The affected systems are Android devices that incorporate the vulnerable bootloader component distributed by Google. No specific Android release versions are listed, meaning any device using the impacted bootloader revision is potentially at risk. All devices operating the Android operating system are therefore considered affected until the vendor issues a patch.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate severity, reflecting the risk of system-level privileges if the flaw is exploited. The EPSS score of less than 1 % shows a low likelihood of exploitation, yet because the flaw requires no user interaction and is solely local through the bootloader component, an attacker with physical or local access can readily elevate privileges. The vulnerability is not listed in CISA KEV, but the local nature of the exploit makes it a significant risk for devices that have not yet received the patch.
OpenCVE Enrichment