Impact
A logic error in gsa_sw_pk_hash_compare within image-auth-srv.c, classified as a failure to secure a privilege decision (CWE-693), may allow a local user to gain system execution privileges with no user interaction. This flaw could enable the attacker to run privileged code or modify system configuration, affecting the confidentiality, integrity, and availability of the device.
Affected Systems
Android Operating System, specifically the image authentication service used in Pixel devices. No specific product versions are listed, so all devices running the affected component may be vulnerable until a patch is released.
Risk and Exploitability
The CVSS score is 6.7, indicating medium severity. The EPSS score is less than 1%, suggesting a low probability of exploitation but not impossible. The vulnerability is not listed in CISA's KEV catalog, implying no widely known exploitation yet. Exfiltration or malicious code that runs at system level could be achieved by an attacker who is able to elevate its privileges without user interaction. The likely attack vector is local privilege escalation on an Android device, requiring the attacker to run code on the device but not needing special network or remote access.
OpenCVE Enrichment