Impact
An out‑of‑bounds write can be triggered by a heap buffer overflow within the Android Cellular Modem, allowing an attacker to write beyond allocated memory. This leads to a remote privilege escalation that does not require any additional execution privileges or user interaction. The vulnerability therefore can grant an attacker elevated rights on the device without needing to compromise a user account or obtain code execution.
Affected Systems
All Google Android devices that incorporate the vulnerable cellular modem firmware are potentially affected, regardless of the OS version or specific firmware build, as no version details are disclosed in the advisory.
Risk and Exploitability
The CVSS score of 8.8 categorises the flaw as high severity, while the EPSS score of <1% indicates a very low yet non‑zero probability of real‑world exploitation. The likely attack vector is remote, inferred from the description that the flaw can be triggered via crafted cellular traffic, and no user interaction is needed. Although the vulnerability is not listed in CISA's KEV catalog, its impact manifests as an ability to bypass normal access controls and obtain elevated privileges on the device.
OpenCVE Enrichment