Impact
The flaw resides in the getAllSessions function across severalC the function to treat requests from a lower‑privilege context as if they were from a higher‑privilege context, allowing a local user to invoke the function and read session details that should remain protected. Because no additional execution privileges or user interaction are required.
Affected Systems
The vulnerability affects the Google Android platform. No specific Android releases or version numbers are listed, so any device that includes the flawed getAllSessions implementation is potentially at risk until a patch is issued.
Risk and Exploitability
The EPSS score is below 1%, indicating an extremely low likelihood of exploitation. The CVSS score of 3.3. Because the attack requires only local access and no user interaction, the overall risk is low to moderate. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment