Impact
Android’s Setup Wizard has a confused‑deputy flaw that can force the device to connect to a malicious network. By hijacking this network path, an attacker can obtain local privilege escalation without needing extra execution rights. The vulnerability lies in the Setup Wizard’s improper handling of network permissions and does not require any user interaction.
Affected Systems
Any Android device that includes the default Setup Wizard component is potentially affected. The CVE record does not list specific version ranges, so devices running Android with the bundled Setup Wizard may be vulnerable.
Risk and Exploitability
With a CVSS score of 7.8 the severity is moderate‑high, and the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. Because the flaw can be abused without user interaction, an attacker with local access or a pre‑compromised device can exploit it immediately. The issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment