Impact
In SettingsFragment, the getItemList method can be exploited by a local attacker through a misleading or insufficient UI that bypasses user interaction. The flaw permits an attacker to elevate privileges without additional execution rights, allowing local privilege escalation. The vulnerability is triggered without user involvement, meaning the attacker can execute it automatically once the device is compromised.
Affected Systems
Google Android is flaw located in the SettingsFragment component of the Android framework. No specific affected versions are listed, so the issue applies to any Android build that contains the vulnerable getItemList method.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and the EPSS score is below 1%, indicating a low probability of exploitation. The vulnerability is not in the CISA KEV catalog, suggesting it may not be actively exploited; however, as the attack vector is a local exploit that can run without additional execution privileges, operators should regard this as a high‑risk local privilege escalation. The likely attack path is inferred to be a local privilege escalation via UI bypass.
OpenCVE Enrichment