Impact
The flaw resides in the setupLayout method of PickActivity.java, where a confused deputy can bypass the "Install unknown apps" security restriction. This misuse of privileges allows an attacker who already has access to the device to install applications without the normal user consent or elevated execution rights, resulting in local privilege escalation. The vulnerability does not require the user to perform any action, so exploitation can occur solely through local interaction with the device.
Affected Systems
operating system and include the vulnerable PickActivity component are impacted. No specific version range is announced, so any Android release containing this activity should be considered at risk until a vendor update is applied.
Risk and Exploitability
The CVSS score of 7.8 denotes a moderate severity level. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Because the attack does not depend on user interaction, a local attacker can trigger the vulnerable activity and bypass the unknown-app install restriction, achieving local privilege escalation. The weakness relates to insecure permission handling (CWE-441).
OpenCVE Enrichment