Impact
The serviceClassExists method in Android's InCallController contains a logical error that can be abused to execute arbitrary code with system privileges. This flaw, identified as a CWE‑693 vulnerability, allows an attacker to elevate their privilege level on a device, effectively taking full control of the operating system without the need for additional privileges or user interaction.
Affected Systems
The vulnerability affects the Android InCallController component across all Google Android devices that include this module, with no specific version information provided.
Risk and Exploitability
Exploitation requires local access to the device; no remote vector or user interaction is needed. The CVSS score of 7.8 classifies it as a high severity vulnerability; the EPSS score of <1 % indicates a very low but nonzero probability of active exploitation. Because it is not listed in the CISA KEV catalog, there are no known active exploits, but the high impact would result in complete system compromise if triggered.
OpenCVE Enrichment