Impact
Android contains a permission bypass that allows unauthorized access to multiple URI endpoints. This flaw permits a local attacker to elevate privilege without needing user interaction or additional execution rights. The vulnerability can be used to read or write protected system resources, compromising confidentiality, integrity, and availability.
Affected Systems
All Android builds that include the vulnerable URI handling code are affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score below 1% suggests that exploitation is unlikely at present. The flaw does not require user interaction; based on the description, it is inferred that a local attacker could trigger the vulnerable URI and elevate privileges. Although the vulnerability is not listed in the CISA KEV catalog, the potential for local privilege escalation makes it a priority.
OpenCVE Enrichment