Impact
There is a race condition that can result in a use‑after‑free. When the freed memory is accessed again, the program flow can be hijacked and arbitrary code can run without requiring elevated privileges. This flaw maps to CWE‑362 (Concurrent Modification). The description notes that exploitation does not need user interaction, so a malicious application or any running process that can trigger the race condition can be used.
Affected Systems
Google’s Android is listed as the vendor. No specific product versions are given, so any Android device that includes the affected components is potentially vulnerable. The actual vulnerable code likely resides in core system libraries that are common to multiple Android releases.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level, while the EPSS score of less than 1 % points to a low but nonzero likelihood of exploitation. The CVE is not in CISA’s KEV catalog. Exploitation does not require user interaction, so a malicious application or any running process that can trigger the race condition can be used by an attacker. Although the low EPSS score suggests limited widespread exploitation, the high CVSS and lack of user interaction make the overall threat level high.
OpenCVE Enrichment