Impact
A logic error in Android’s ac_init_policy function within init.c allows a local user to bypass permission checks, granting higher privileges without requiring any additional execution privileges or user interaction. This flaw can compromise system integrity and potentially give an attacker full device control.
Affected Systems
The defect resides in the core init.c code that runs on all Android devices using Google’s Open Source Android framework. All builds of the operating system that include the unpatched init.c are susceptible, regardless of device brand or version, until the fix is applied through a security update.
Risk and Exploitability
The EPSS score for this vulnerability is reported as less than 1%, and it is not included in the CISA KEV. Because no user interaction is needed, any local attacker can elevate privileges, potentially leading to full device compromise. The severity score of 8.4 indicates a high risk, while the low EPSS suggests the likelihood of widespread exploitation is currently small but present in environments where devices lag behind security updates.
OpenCVE Enrichment