Impact
The vulnerability, as described, is an out-of-bounds read in Samsung Opensource rLottie that permits overreading buffers. This can expose internal memory contents and potentially confidential data, aligning with the CWE-125 classification. The CVSS score of 4.4 indicates moderate severity.
Affected Systems
rLottie, the Samsung Open Source project, is affected specifically in the commit identified by 25648aef19187b3f87f4d9420b8d761453ad4630. No vendor supplied version list was provided.
Risk and Exploitability
EPSS score of <1% indicates a low probability of exploitation, and the vulnerability is not listed in KEV. The moderate CVSS score of 4.4 reflects the potential for an attacker to read arbitrary memory. Exploitation could lead to data leakage if the affected component processes untrusted input. No exploitable code path is described, so the vulnerability requires local or privileged context as a prerequisite.
OpenCVE Enrichment