Impact
The vulnerability arises from an integer overflow in multiple functions within rw_t3t.cc, potentially causing an out‑of‑bounds write. Exploitation of this flaw can provide a local attacker with elevated privileges on the Android device without requiring any user interaction or additional execution rights.
Affected Systems
The affected product is Google Android as documented by the CNA. No specific Android release or build version is provided in the data, so any device running a version that contains the vulnerable rw_t3t.cc implementation is potentially at risk.
Risk and Exploitability
The EPSS score of <1% indicates a very low likelihood of public exploitation. The CVSS score of 7.8 classifies the vulnerability as a high severity local privilege escalation. It is not listed in the CISA KEV catalog. The flaw does not need user interaction and can be triggered by any process that exercises the vulnerable functions, allowing local attackers to elevate privileges once they have a foothold on the device.
OpenCVE Enrichment