Impact
The vulnerability resides in Android’s VoiceInteractionManagerService, where inadequate handling of resource allocation can lead to persistent exhaustion. Attackers can trigger a local denial of service without requiring any elevated privileges. Because the flaw does not need user interaction, any local user or malicious application can exploit it. The weakness aligns with CWE-770 (Allocation of Resources Without Limits). The primary impact is disruption of the voice interaction subsystem, potentially rendering the device unusable until restarted.
Affected Systems
The affected vendor is Google, specifically the Android operating system. At present, no specific Android version range is listed in the advisory. Administrators should verify whether their current device builds include the VoiceInteractionManagerService components referenced in the description.
Risk and Exploitability
The CVSS score is 5.5, and the EPSS score is <1%, indicating a low probability of exploitation. However, the vulnerability requires only local access and no special privileges, meaning any local user can exploit it. While the issue is not yet listed in CISA KEV, the ability to cause a persistent denial of service creates a moderate to high risk to device availability. The likely attack vector is local, with a straightforward trigger that consumes system resources until a reboot or service restart occurs.
OpenCVE Enrichment