Impact
During the onCreate lifecycle of SetupPassthroughActivity, an Intent can be accepted and forwarded to startActivity without proper validation, enabling an attacker to launch an arbitrary component. This bypass of internal component isolation allows the attacker to access data or functionalities normally restricted to the application. The flaw does not require any execution privileges beyond what a legitimate user has and does not provide immediate remote exploitation.
Affected Systems
The affected product is Google Android, specifically the SetupPassthroughActivity component of the system setup flow. No specific Android version or build string is mentioned in is likely present in any build that includes this activity without the proper intent validation safeguards.
Risk and Exploitability
The CVE has a CVSS score of 7.3, an EPSS score of <1%, and is not listed in the CISA KEV catalog, suggesting that the vulnerability is not widely exploited or tracked. However, because it enables local privilege escalation, the risk to a device is high if a malicious actor can lure a user into interacting with the vulnerable intent. The attacker would need user interaction to trigger the targeted Intent, but once triggered, the escalation allows further compromise.
OpenCVE Enrichment