Impact
In some versions of the Android bootloader a permission check is omitted, allowing an attacker to gain System execution privileges without any user interaction. This missing check is a form of Broken Access Control (CWE-862).
Affected Systems
The flaw exists in Google Android devices; all Android bootloaders that contain the missing permission check are affected. Specific affected versions are not listed, so any Android device running a bootloader containing this check could be vulnerable.
Risk and Exploitability
The exploit requires local access to the device and occurs during the boot process, so no user interaction is needed. The EPSS score of < 1 % indicates a very low probability of widespread exploitation, but the CVSS score of 6.7 reflects moderate severity. The vulnerability is not listed in CISA KEV, and a successful attack would grant system execution privileges, effectively compromising the device.
OpenCVE Enrichment