Impact
A flaw in several LocalImageResolver.java functions allows an attacker to craft a DNG image that bypasses the usual rendering check, causing the Android system to enter a persistent denial‑of‑service state from which it can escalates privileges. This is an input‑validation error that lets attackers supply data the system mistakenly accepts as valid, leading to loss of service and elevated rights without the need for additional execution privileges.
Affected Systems
Android operating systems from Google. No specific vendor product versions are listed in the available data.
Risk and Exploitability
The vulnerability can be exploited remotely without user interaction, making it attractive to attackers. The EPSS score is less than 1 %, indicating a low probability but not zero of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 8.8 indicates a high severity, compromise device stability and privilege.
OpenCVE Enrichment