Impact
In Android's WindowState.java, a logic error in setHiddenWhileSuspended allows an overlay to bypass normal visibility restrictions, enabling a local attacker to elevate privileges without needing any additional execution rights. The flaw does not require user interaction, making it easier for an attacker with local device access to exploit the vulnerability and gain higher privileges.
Affected Systems
The issue targets Google:Android operating systems that include the affected WindowState.java component. No specific version numbers are listed, so any Android build containing the unpatched code is potentially susceptible until a vendor update is applied.
Risk and Exploitability
The flaw has a CVSS score of 7.8 and an EPSS score of <1%, and is not listed in CISA's KEV catalog. The combination of local privilege escalation and no user interaction suggests a moderate yet tangible exploitation potential. Attackers can trigger the bypass by launching a malicious overlay or manipulating the system UI from a local app, exploiting the logic error to override hidden state flags.
OpenCVE Enrichment