Impact
An integer overflow in several parts of the Android operating system can trigger an out‑of‑bounds write that allows a local attacker to gain higher privileges without needing additional execution rights. The flaw results from unvalidated numeric calculations that overflow, leading to memory corruption. It is classified as CWE‑190 and can let a low‑privileged user modify kernel memory or alter program state, enabling privilege escalation.
Affected Systems
The vulnerability affects devices running Google:Android, but the advisory does not list specific firmware versions. Users should refer to the Android security bulletin linked in the references to determine whether their device build is impacted.
Risk and Exploitability
The CVSS score is 7.8, indicating a high severity flaw. Exploitation requires local access to the device; no user interaction is needed. EPSS data is unavailable, so the precise exploitation probability is unclear, but the high CVSS suggests significant risk. The issue is not listed in the CISA Known Exploited Vulnerabilities catalog, so no widespread exploitation has been reported yet.
OpenCVE Enrichment