Impact
The vulnerability originates in the gem_msg.c component of the Android operating system, where the is_pd_allowed function lacks a required permission check. This omission allows an attacker with system execution privileges to bypass normal authorization controls and access sensitive user data. The flaw creates a local information disclosure path that can expose protected information without needing any user interaction.
Affected Systems
Affected systems are Android devices running the Google Android platform. Specific versions are not enumerated in the advisory; the bug exists in any build that includes the vulnerable gem_msg.c code.
Risk and Exploitability
Because the flaw requires system‑level privileges, the attack surface is limited to local attackers who can gain such privileges through exploits or pre‑installed malicious components. The CVSS score is not provided, but the impact on confidentiality could be significant. The EPSS score is unavailable and the vulnerability is not present in the CISA KEV catalog, suggesting no widespread, known exploits at this time. Nonetheless, the module’s lack of authorization checks makes it a high‑risk security weakness within the device’s privileged services.
OpenCVE Enrichment