Impact
The flaw is an out‑of‑bounds read within fsck.c’s read_boot_region function caused by a heap buffer overflow. An attacker with local access can exploit this without additional privileges or user interaction, potentially allowing escalation of privileges on the device.
Affected Systems
Google: Android devices are affected by this vulnerability; specific model or software version information is not provided in the available data.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8 and is rated as a local privilege escalation. No public exploit is documented and the EPSS score is <1%, indicating a low probability of exploitation. Because the issue is not listed in CISA KEV, the likelihood of immediate exploitation appears low, though vendors are encouraged to address it promptly.
OpenCVE Enrichment