Impact
An improper cast in MatroskaExtractor.cpp within Android’s Media framework leads to an out‑of‑bounds write. This memory corruption permits an attacker to execute arbitrary code on, representing a potential remote code execution flaw.
Affected Systems
The defect is present in Google Android; specific affected releases are not listed. Update all devices to the latest Android release that contains the MatroskaExtractor fix to eliminate the vulnerability.
Risk and Exploitability
The EPSS score is < 1% and the CVSS score is 8.8, yet the vulnerability is not currently in CISA's KEV catalog. The likely attack vector involves delivering a crafted Matroska file via Bluetooth, Wi‑Fi, or other media ingestion mechanisms, without requiring user action. Because no additional privileges are needed, any user of an affected device is at risk. Successful exploitation would give an attacker full control of the device, enabling data exfiltration, manipulation, or service disruption.
OpenCVE Enrichment