Impact
In multiple functions of XmpDataParser.java, an improper data sanitization logic flaw allows sensitive data to be read without additional execution privileges. The issue does not require user interaction and can be triggered by a locally trusted application or malicious file, leading to the disclosure of confidential information such as user preferences, media metadata or potentially credential data stored in the XMP format.
Affected Systems
The vulnerability affects Android devices manufactured by Google. No specific build numbering is cited in the advisory, so any Android installation that contains the vulnerable XmpDataParser.java module is potentially impacted, regardless of RAM or OS tier.
Risk and Exploitability
The flaw is local; an attacker must have access to the device and the ability to execute a malicious app or place a file that triggers XMP parsing. The CVSS score of 3.3 reflects a moderate impact on confidentiality. The EPSS score of less than 1% indicates a very low probability of exploitation, and the flaw is not listed in CISA KEV. Nonetheless, because the affected platform is widely deployed, the vulnerability warrants immediate attention.
OpenCVE Enrichment