Impact
In RoutingManager.cpp, a missing bounds check in checkUiccListenConfigNeeded can cause an out‑of‑bounds write to memory. This flaw falls under CWE‑120 and can be leveraged to achieve remote code execution with no additional privileges. Because the vulnerability does not require user interaction, a malicious actor could trigger it whenever the affected component is executed.
Affected Systems
The flaw affects the Android platform from Google. No specific Android OS version is listed in the advisory, so all releases that contain the unpatched RoutingManager.cpp are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.0 indicates a high severity, with exploitation capable of compromising the device. The EPSS score of < 1% suggests a very low likelihood of exploitation currently. Based on the description, it is inferred that the likely attack vector is local or network interaction with the RoutingManager component, as the flaw does not require user interaction or privilege escalation. Because the vulnerability is not listed in KEV, it may not be actively exploited yet, but the high severity warrants monitoring.
OpenCVE Enrichment