Impact
The vulnerability originates in several methods of DevicePolicyManagerService.java where inadequate input validation allows a desynchronization between the in‑memory state and persisted data, which can lead to a local denial‑of‑service without requiring elevated privileges or user interaction.
Affected Systems
The affected products are all Google Android devices that include the vulnerable DevicePolicyManagerService; no specific version information is provided, so any device running the affected Android release may be at risk until a patch is released.
Risk and Exploitability
Because the flaw can be triggered locally without privileged access or user involvement, an attacker who can run code on the device can repeatedly restart services or destabilize the system. The CVSS score of 5.5 indicates moderate severity, the EPSS score is unavailable, and the vulnerability is not yet listed in CISA’s KEV catalog, but it still poses a moderate risk for affected users.
OpenCVE Enrichment