Impact
In AccountsDb.java a logic error allows the fast reboot protection (FRP) check to be bypassed, enabling a local user to elevate privileges without needing any additional execution privileges or user interaction, an improper access control flaw that can compromise device integrity.
Affected Systems
The security flaw is present in Google Android operating systems; specific version information is not disclosed in the advisory.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low but existing likelihood of exploitation. Because no user interaction is required and the escalation is purely local, an attacker can exploit the flaw easily once the logic error is present. The CVSS score of 7.8 classifies the issue as high severity, reflecting the significant risk to device integrity if left unpatched.
OpenCVE Enrichment