Impact
A logic error in the resolveActivity method of ActivityStarter.java allows malicious apps to redirect intents to system components, enabling an app to trigger privileged actions without the user’s knowledge, thereby providing a path to local elevation of privileges. The flaw can be used to compromise applications or system services by exploiting the trust granted to intent handlers.
Affected Systems
The vulnerability affects Google Android devices; the public advisory does not list specific OS versions, so any build that contains the vulnerable ActivityStarter code is potentially impacted until an official fix is released.
Risk and Exploitability
The exploit is local; an attacker who can install or execute code on the device can craft malicious. The EPSS score of <1% indicates a low probability of exploitation, and the CVSS score of 7.8 reflects high severity. Although not cataloged in CISA KEV, the potential for local privilege escalation makes the risk significant for affected devices.
OpenCVE Enrichment