Impact
In the Android runtime source file rw_mfc.cc, the function rw_mfc_handle_read_op performs an incorrect bounds check, enabling a local attacker to write data past the end of a buffer. This could lead to a local privilege escalation without requiring additional execution privileges or user interaction. An exploit could corrupt memory, potentially allowing an attacker to elevate privileges to a local privileged user.
Affected Systems
The flaw affects Google’s Android contain the vulnerable MFC handling component. Versions are not explicitly disclosed, but any build that includes the uncorrected rw_m or unsupported ROMs that have not applied the official patch are likewise exposed.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity Local Privilege Escalation. The EPSS score of less than 1% suggests that, although the vulnerability is severe, the probability of exploitation in the wild is currently low. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is local; it does not require user interaction and no additional execution privileges beyond the process’s existing permissions are needed. The exposure remains significant in environments where untrusted applications run with elevated rights.
OpenCVE Enrichment