Impact
The vulnerability arises from a logic error that allows improper sanitization of data. This flaw permits the disclosure of confidential information on the target device without requiring any additional execution privileges. Because the attack does not depend on user interaction, any user who owns the device could potentially read private data exposed by the flaw. The weakness falls under the class of information exposure due to inadequate data handling.
Affected Systems
Android operating systems provided by Google are affected. No specific version range is listed in the available data, so any installed Android build that contains the implicated code may be vulnerable.
Risk and Exploitability
The CVSS score is 3.3, indicating a low severity. The EPSS score is < 1. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited. The attack could be carried out silently by any process on the device that can trigger the logic error, making it straightforward for attackers with local access to exploit.
OpenCVE Enrichment