Impact
A missing permission check in the onCreate method of ConfirmDeviceCredentialActivity.java allows an application to read or alter device credentials without authorization. This vulnerability is a CWE-862 problem. The flaw can expose sensitive credential data, compromising confidentiality but not enabling execution of arbitrary code or service disruption. The vulnerability is strictly local and does not require elevated privileges beyond those of the running application.
Affected Systems
Android operating systems that include the vulnerable ConfirmDeviceCredentialActivity component. Devices running a Google Android version that has not yet received the security update addressing this missing permission check are affected.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is local, requires no user interaction, and can be triggered by any application with sufficient permissions. Based on the description, it is inferred that an attacker who obtains credential data could potentially leverage it for further attacks, though this extension goes beyond the explicit disclosure impact.
OpenCVE Enrichment