Impact
An integer overflow occurs in the tt_face_colr_blend_layer function of ttcolr.c, which may allow an attacker to execute arbitrary code. The flaw does not require any additional execution rights and does not need user interaction to be exploited.
Affected Systems
The vulnerability affects Google's Android operating system. Specific affected build numbers, release versions, or patches are not supplied in the advisory, so all Android installations that include the vulnerable ttcolr.c implementation are potentially impacted. No version ranges are documented publicly.
Risk and Exploitability
The CVSS score is 7.8, which indicates moderate to high severity. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating limited public exploitation data to date. Based on the description, the attack vector is local and does not require user interaction, meaning any user or application running with access to the vulnerable component could trigger the flaw. This lack of dependency on user action raises the likelihood of successful exploitation in a compromised environment.
OpenCVE Enrichment