Impact
The vulnerability resides in the addCreatorToken method of ActivityManagerService.java, where a logic error allows a bypass of Intent redirection protections. An attacker with local access can redirect privileged intents to malicious code, thereby elevating their own privileges without requiring any additional execution rights. The flaw does not demand user interaction, and no extra privileges are needed beyond local device possession.
Affected Systems
Android operating systems from Google are affected, including any devices that use the default ActivityManagerService component. No specific Android release versions are listed in the data provided, so all versions are considered potentially vulnerable until a patch is released.
Risk and Exploitability
The CVSS score is 7.8, and the EPSS score is < 1%. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known exploits at the time. The attack vector is local, requiring device access without user interaction. Because the CVSS reflects a high-impact flaw and the EPSS indicates a low probability of exploitation, the overall risk is moderate; devices that have not yet received an update remain susceptible until a vendor release is applied.
OpenCVE Enrichment