Impact
The vulnerability is located in the assertSafeToStartCustomActivity method confused deputy scenario permits unauthorized read or write access to private device files that does not require additional execution rights or any user interaction to exploit.
Affected Systems
Google Android devices that include the affected AppRestrictionsFragment component. The exact affected versions are not listed in the data provided, so any build containing the referenced code path may be vulnerable.
Risk and Exploitability
The flaw is local and can be leveraged by any user with local access, and the vulnerability does not involve remote exploitation or execution privileges beyond file access. User interaction is not needed for exploitation. The CVSS score of 7.8 indicates high severity, the EPSS score is < 1% reflecting a low exploit probability, and the issue is not listed in the CISA KEV catalog, but the potential impact on confidentiality and integrity of private files is significant.
OpenCVE Enrichment