Impact
The vulnerability is a confused deputy flaw in Android’s screenArgsForPermissionCheckIfAny routine, allowing an attacker to bypass normal permission checks and read data that should be protected by app‑level permissions. The resulting local information disclosure occurs without providing the attacker with additional execution privileges or requiring any user interaction, as stated in the advisory. The likely effect is that a malicious or compromised application could access sensitive data owned by other apps or the system.
Affected Systems
Google’s Android platform contains the vulnerable screenArgsForPermissionCheckIfAny routine across multiple source files. No specific Android version is cited, indicating that any pre‑patched build may be affected. Devices running current builds that have not yet received the security update described in the 2026‑09‑01 bulletin may still be vulnerable.
Risk and Exploitability
The CVSS base score of 3.3 classifies the flaw as low severity, and the EPSS score of less than 1 % signifies a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is purely local: a malicious or compromised app can directly invoke the routine without needing elevated privileges. While the probability of exploitation remains low, any device that stores sensitive data could still be exposed to inadvertent disclosure if the flaw is not mitigated.
OpenCVE Enrichment