Impact
In certain Android system components, a confused deputy flaw allows an application to read or write files that it should not have permission to access. This flaw does not require any further execution privileges or user interaction; an of the trusted component to modify or read protected files. The potential consequence is the compromise of sensitive data or the alteration of critical system files, resulting in an elevation of local privileges.
Affected Systems
Google Android devices are affected. The specific versions are not listed in the advisory, so any device running the vulnerable components may be at risk.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation likelihood is low but uncertain. Because the attacker does not need to execute code or spoof user interaction, the practical attack vector is local. The CVSS score is 7.8, indicating high severity. Monitoring for anomalous file access and applying any available security patches remain the primary defensive measures.
OpenCVE Enrichment