Impact
PermissionsManager.checkReadPermission in Android Wear omits a required permission verification, allowing any local user to monitor sensitive device state data. The vulnerability results in local information disclosure without demanding elevated execution privileges or user interaction, meaning an attacker already present on the device can exploit it directly.
Affected Systems
The flaw affects components of Google’s Android Wear operating system. All devices running Android Wear without a fixed update are vulnerable; firmware version details are not provided, so the issue applies broadly to devices that have not yet installed a security update.
Risk and Exploitability
The vulnerability receives a CVSS score of 10, indicating a critical level of risk. The EPSS score listed is less than 1 % (0.00194), suggesting a very low but non‑zero probability of exploitation in the wild; the flaw is not included in the CISA KEV catalog. The attack vector is local and does not require user interaction, implying that an attacker with physical or remote access to the device can exploit it readily once the device is in the attacker’s control.
OpenCVE Enrichment