Impact
The Android framework’s onActivityResult method in AppWidgetConfigActivityProxy.java contains a flaw that grants an application permission to access a URI it should not be able to access. The flaw also corresponds (CWE‑441), as the unauthorized URI permission is granted based on user‑supplied data. This is a classic confused‑deputy vulnerability that enables an app to elevate its privileges locally without needing elevated execution rights. The result is that an attacker with local device access can gain unauthorized access to resources protected behind URI permissions, potentially compromising confidential data or enabling further exploitation.
Affected Systems
Google Android devices are affected whenever the AppWidgetConfigActivityProxy component processes widget configuration callbacks. No specific Android release or API level is identified in the advisory, implying that the vulnerability could exist across multiple releases until a patch is applied. Users of any Android device running a version that has not yet incorporated the fix are at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score of < 1% indicates a very low exploitation probability at present, but the local nature of the attack means that an attacker who already has physical or local access can exploit the flaw independently of remote vectors. The vulnerability is not listed in the CISA KEV catalog, yet its local privilege escalation potential warrants prompt attention. Exploitation requires no user interaction; an attacker simply needs to trigger the activity result flow used by applications that configure widgets.
OpenCVE Enrichment