Impact
A logic error in the Android ClipboardService allows a local user to bypass multi-user isolation, enabling them to perform actions on another user’s account without needing additional privileges. The flaw does not require any user interaction, so exploitation can occur automatically whenever the device is in use.
Affected Systems
The vulnerability affects the ClipboardService of the Google Android platform. No specific Android version is listed in the advisory, so all supported versions that include the unpatched service are potentially impacted.
Risk and Exploitability
The vulnerability is not listed in the CISA KEV catalog, and the EPSS score of less than 1% indicates a very low probability of exploitation. However, the CVSS score of 7.8 still represents high severity, and based on the description, the flaw allows a local privilege escalation that can be exploited by any user on the device with no additional attack surface. The likely attack vector is local, requiring only that the user have access to the device.
OpenCVE Enrichment