Impact
The issue is a heap buffer overflow identified in multiple code locations within the Android operating system. Because the overflow occurs on the heap and can lead to arbitrary code execution, an attacker could run malicious code with the same privileges as the affected process. No additional privileges or user interaction are required to exploit the flaw, which elevates its seriousness.
Affected Systems
The vulnerability is reported to affect Google Android devices. No specific versions or build identifiers were provided, so all Android releases that include the vulnerable components at the time of the advisory are considered exposed until a fix is applied.
Risk and Exploitability
With a CVSS score of 9.8 the flaw is deemed critical. The EPSS score is not available, and it is not currently listed as a Known Exploited Vulnerability. The lack of user interaction and the remote nature of the exploit, combined with the high severity rating, suggest that the risk of exploitation is significant, especially for devices that are not updated promptly.
OpenCVE Enrichment