Impact
The vulnerability resides in Android's AnnotationProcessor.cpp within the AppendCommentLine function. It results from inadequate input validation, allowing crafted data to be processed without proper checks. This flaw can be used by a local user to elevate privileges, enabling access to higher-level functions. The weakness falls under CWE-20, Input Validation, as the code fails to verify input boundaries or content.
Affected Systems
The affected vendor is Google, specifically Android. All Android installations that include the vulnerable version of AnnotationProcessor.cpp are impacted. No version range is specified, so users should check their platform build against the Android security bulletin referenced in the advisory.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high severity for this flaw. Though an EPSS score is not available, the lack of that metric does not reduce the danger of this local privilege escalation. No user interaction is required, so an adversary with local access can exploit the weakness at will. The vulnerability is not yet listed in the CISA KEV catalog, but its high severity warrants prompt attention.
OpenCVE Enrichment