Impact
In the GameManagerService of Android, the parseInterventionFromXml function can consume excessive resources, causing the device to crash permanently. The flaw does not require administrative privileges, nor user interaction; an attacker could simply trigger the vulnerable XML parsing path to bring the system down. The primary impact is a local denial of service, rendering the device unusable until restarted or patched.
Affected Systems
Android devices running the GameManagerService component are impacted, specifically editions of the operating system distributed by Google that include the referenced GameManagerService module. No specific Android version is listed, so any device with this component is potentially vulnerable until it receives the security fix.
Risk and Exploitability
The vulnerability is exploitable locally without any special privileges, making it straightforward for an attacker with physical or local access to cause service interruption. The CVSS score of 5.5 indicates medium severity. The EPSS score of < 1% shows a very low but non‑zero likelihood of exploitation, and the vulnerability is not currently listed in CISA's KEV catalog. Nevertheless, the risk remains significant given the ease of exploitation and the severity of the denial of service it can trigger.
OpenCVE Enrichment