Impact
The vulnerability resides in the gf_ta_test_set_config function of gf_ta_test.c, where improper input validation can cause an out‑of‑bounds write. If an attacker supplies crafted input to this function, memory beyond the intended buffer may be overwritten, allowing an elevation of local privileges on the device. The flaw can be triggered without any remote interaction or prior privileged rights; local access to the device’s test framework is sufficient and no user interaction is required.
Affected Systems
Affected systems are Android devices running Google’s Android operating system with an unpatched gf_ta_test module. The advisory does not specify particular models, but any device that has not received the security update that fixes the out‑of‑bounds write is potentially vulnerable.
Risk and Exploitability
The CVSS base score of 7.8 signals a high‑severity flaw. The EPSS score of < 1% indicates a very low exploitation probability, and the issue is not listed in the CISA KEV catalog. However, the local attack vector means an attacker with physical or local software access can exploit the vulnerability. No active exploitation is known, but the combination of a high score and local access encourages remediation.
OpenCVE Enrichment