Impact
The vulnerability arises from a missing permission check in the openFile routine of AppFuseBridge.java, an integral part of the Android framework. The omission allows any local app or process to read protected files through the exposed file opening interface, resulting in information disclosure. This weakness is classified as CWE-693 (Improper Check of Security‑relevant Information). Because no elevated privileges are required, a local attacker can extract data that would otherwise be protected by the platform’s permission model.
Affected Systems
Google Android builds that include the AppFuseBridge component are affected. The advisory does not specify particular hardware or OS versions, implying that all Android releases incorporating this component without the patch may be vulnerable. The flaw resides in the core framework rather than a third‑party app.
Risk and Exploitability
The calculated CVSS score is 3.3, indicating low severity. EPSS is below 1%, showing a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV, and no public exploits are documented. The attack vector is purely local; an adversary already on the device could invoke the openFile function from a malicious or compromised app without user interaction. Because missing authorization (CWE-693) leads to insecure data exposure, the risk to individual devices is low but confined to local contexts.
OpenCVE Enrichment