Impact
A permission bypass exists in the ActivityTaskManagerService.startNextMatchingActivity method, allowing a local attacker to elevate privileges without executing additional code or prompting the user. The flaw is a classic confused‑deputy scenario, classified as CWE‑441, in which privileged operations are performed on behalf of lower‑privileged callers.
Affected Systems
Android devices running the Android operating system, including any build that contains the vulnerable ActivityTaskManagerService component, are affected until the vendor releases a patch. Version specifics are not disclosed in the advisory.
Risk and Exploitability
The vulnerability is local and does not require user interaction. An attacker who can invoke the vulnerable method—such as a malicious app—can raise its privileges to that of the system. The CVSS score of 7.8 indicates high impact, while the EPSS score of less than 1% suggests a low likelihood of current exploitation. The flaw is not listed in the CISA KEV catalog, but the impact remains significant for any device that has not applied the official fix.
OpenCVE Enrichment