Impact
The vulnerability exists in several functions within "rw_t5t.cc" where a bounds check is omitted, allowing an out‑of‑bounds read. This flaw can expose confidential data located past the intended buffer and does so without requiring elevated privileges or any user interaction. The impact is strictly the potential to read local memory data that should remain inaccessible to the executing process.
Affected Systems
The affected product is Google Android. Affected components include the "rw_t5t.cc" source files; specific device models or OS versions are not listed in the advisory, so any Android build that includes these functions may be vulnerable.
Risk and Exploitability
The CVE carries no EPSS score and is not catalogued in CISA KEV, indicating a current lack of widespread exploitation reports. The attack vector is local and requires no additional execution privileges or user action. The severity depends on the sensitivity of the disclosed data; while the vulnerability does not enable privilege escalation or remote code execution, it represents a notable risk for privacy and integrity if exploited on a target device.
OpenCVE Enrichment