Impact
The vulnerability resides in the CPM component, where a confused deputy allows an adversary with system execution privileges to read data it is not authorized to access. No user interaction is required, and the flaw can result in the disclosure of sensitive information that normally would be protected by privilege restrictions. This information leakage can compromise user data and compromise trust in the Android platform.
Affected Systems
Google Android devices running the Android operating system are affected. The CVE description does not specify particular Android OS releases, so any device with this vulnerability present may be susceptible.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, and the EPSS score of 0.00071 (<1 %) shows a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local system execution privileges; no remote code execution or elevated privileges beyond system level are needed. Attackers would need to attain local system privileges and then invoke CPM to read protected data.
OpenCVE Enrichment