Impact
A heap buffer overflow exists in the rw_mfc_handle_read_op function of Android’s MFC subsystem, which can be triggered without any user interaction or elevated privileges. An attacker who can supply crafted input to this read operation can overwrite heap memory and execute arbitrary code on the device.
Affected Systems
This vulnerability affects Android devices running the Google Android operating system. No specific version range is disclosed, so all releases that include the unpatched rw_mfc.cc implementation are potentially at risk.
Risk and Exploitability
The flaw is highly exploitable because it requires no special execution rights and can be triggered remotely. While the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, the CVSS score of 8.8 indicates high severity, and the nature of the vulnerability and its remote execution potential point to a high threat. Attackers can compromise device security by running arbitrary code, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment