Impact
A logic error in the Android media framework’s rw_mfc_handle_read_op routine causes an out‑of‑bounds write that can overwrite memory structures. This flaw does not require any additional execution privileges or a remote attack vector and can be triggered by any local user who initiates the read operation. The result is the elevation of the attacker’s privileges on the device.
Affected Systems
The vulnerability is present in any Android_handle_read_op implementation. No specific version numbers are listed, so all current Android releases prior to the issuance of the official patch are considered at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploits in the wild at this time. Because the attack can occur without user interaction, a local attacker has a realistic chance of exploitation, though the overall likelihood remains low.
OpenCVE Enrichment