Impact
A logic error in multiple areas of the Android operating system creates a use‑after‑free condition, allowing a local attacker to manipulate memory that has already been released. The flaw permits a dangling‑pointer exploit that can read or write protected data without exceeding the current execution privilege level, resulting in an elevation to system or root privileges. The root cause is captured by CWE-693.
Affected Systems
The vulnerability affects all Android devices that contain the vulnerable code path. Exact affected versions are not enumerated in the CVE entry, so any installation whose build includes the unsanitized use‑after‑free logic is potentially impacted. Android devices of all manufacturers that ship the affected OS builds are subject to risk until the vendor releases a patch.
Risk and Exploitability
The CVSS score is 7.8. The EPSS score is reported as less than 1 %, and the flaw is not listed in the CISA KEV catalogue, suggesting no known active exploits. However, exploitation does not require user interaction, by executing code on the target device. The threat level remains significant for unpatched devices, especially where privileged user‑level data is accessible.
OpenCVE Enrichment