Impact
The vulnerability is a logic error in the Video Processing Unit that reads sensitive data without proper authorization, representing a CWE-200 data exposure weakness. An attacker with system execution privileges can exploit the flaw to locally disclose information. The flaw does not require user interaction, enabling abuse after the attacker has already gained local access.
Affected Systems
Google has identified the vulnerability in its Android operating system. No specific device models or OS versions are listed, so the flaw may affect any device running the affected Android build where the VPU component is present.
Risk and Exploitability
The advisory assigns a CVSS score of 4.4, classifying the issue as Low severity. The EPSS score is 0.00077 (<1%) and vulnerability is not listed in CISA’s KEV catalog. Exploitation requires system-level permissions, so only local attackers with elevated privileges can disclose data. Because no user interaction is needed, an attacker who has already compromised the device can read memory or data associated with the VPU. The local nature of the exploitation limits the potential impact to the device itself, but the information disclosed could be sensitive and compromise privacy or facilitate further attacks.
OpenCVE Enrichment