Impact
Based on the description, the vulnerability is an integer overflow in the convertCleanApertureToRect function of Heif can trigger a temporary denial of service without requiring user interaction or elevated privileges. The overflow occurs when processing HEIF files, potentially causing critical components that rely on the function to crash or become unresponsive, resulting in service interruption for the device or protected services.
Affected Systems
The flaw affects Android devices running Google Android where the HeifCleanAperture component is included. No specific version numbers are disclosed in the advisory, so all builds containing this code are potentially vulnerable until a patch is applied.
Risk and Exploitability
The issue is not listed in the CISA KEV catalog. The EPSS score of < 1% indicates a very low probability of exploitation, while the CVSS score of 4.3 points remote delivery of a specially crafted HEIF file to a device or service that decodes such files, and the impact is a temporary service interruption until a system restart or patch. Because no user interaction is required, the vulnerability can be triggered by an adversary with network access that can influence the decoding process.
OpenCVE Enrichment