Impact
An integer overflow in several components of the Android operating system can allow a local user to bypass permission checks. This flaw permits local escalation of privilege without requiring additional execution privileges or user interaction.
Affected Systems
Google Android devices are affected; no specific OS versions or device models are identified in the available data.
Risk and Exploitability
The EPSS score indicates a very low but non‑zero likelihood (< 1%) that the flaw will be exploited in the wild, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 8.4 indicates moderate to high severity. Exploitation requires local access, no remote trigger, and does not need elevated execution privileges. An attacker could potentially gain higher privileges to modify system files or installations, increasing the impact on confidentiality, integrity, and availability of the device.
OpenCVE Enrichment