Impact
A missing permission check in several functions of RangingServiceImpl.java allows a malicious actor to read data from the ranging service without transport layer security or elevated privileges. The flaw can be triggered by a call to the service’s inter‑process interface, so no user interaction is needed. The exposed in a remote information disclosure that places the confidentiality of device location data at risk.
Affected Systems
The vulnerability affects Google Android devices that include RangingService component. No specific Android version numbers are given, so any build running Android and a security update is applied.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity. The EPSS score is below 1%, and the flaw is not listed in CISA KEV, so exploitation likelihood is very low. Because the flaw permits information disclosure without requiring special permissions or user interaction on how sensitive the accessed data is. The most probable attack vector is through an inter‑process call to the ranging service, which can be invoked by another app or system component on the device.
OpenCVE Enrichment