Impact
Android’s initAppLinkTypeAndIntent method in ChannelImpl.java fails to properly validate input, allowing an arbitrary intent to be launched. This flaw can elevate the attacker’s privileges on the device without requiring any precedent access needing user interaction to trigger the malicious intent fault, where malicious intent data can be crafted to execute privileged operations within the Android framework.
Affected Systems
Google Android systems are impacted. No specific Android version numbers are disclosed, so all releases that include ChannelImpl.java are potentially vulnerable until a patch is applied.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, making the precise exploitation probability low. However, because the flaw requires user interaction and relies on improper intent validation, the likelihood of exploitation is moderate. The CVSS score of 7.3 indicates a fairly high severity, and the impact is significant due to privilege escalation, allowing a malicious app or intent to perform privileged actions. Attackers would need to lure a user into launching a crafted link or intent within the Android environment.
OpenCVE Enrichment