Impact
The vulnerability exists in WifiNetworkSuggestionsManager.java of Android, enabling persistent denial of service by exploiting a resource exhaustion flaw. An attacker can trigger unlimited consumption of system resources, leading to service slowdown or crash. The issue requires no elevated privileges and does not need user interaction.
Affected Systems
Android devices, specifically the Google Android platform. Precise affected versions are not disclosed in the CVE data; the vulnerability pertains to the WifiNetworkSuggestionsManager component.
Risk and Exploitability
The vulnerability is local and can be triggered by code running on the device with the same privilege level as the WifiNetworkSuggestionsManager component. The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low but non‑zero exploitation probability. It is not listed in the CISA KEV catalog no elevated privileges are required and user interaction is not needed, the primary risk is a local denial of service manifested as a slowdown or crash of the wifi suggestion service, potentially impacting overall device performance.
OpenCVE Enrichment