Impact
In several places within Android's cryptographic subsystem a logic error allows bypassing proper validation of encryption keys. The flaw lets a local attacker obtain elevated privileges without triggering any additional code execution. The vulnerability is an example of improper local privilege escalation.
Affected Systems
The vulnerability is identified in Google Android devices. No specific OS version was disclosed, but any device running a version that includes the affected code may be impacted. Owners of Android phones or tablets should verify whether their installation incorporates the confirmed vulnerability.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in CISA KE. The CVSS score of 7.8 reflects a high severity for local privilege escalation, and because the flaw does not require user interaction, a local attacker can exploit it readily. The likely attack vector is local exploitation, inferred because the flaw does not require user interaction.
OpenCVE Enrichment