Impact
The vulnerability is an out-of-bounds write in the openLogicalChannel function within Android’s smart card handling code. The missing bounds check can corrupt adjacent memory, allowing a local attacker to modify kernel or system memory. This extension of privileged access can lead to privilege escalation on the device, potentially enabling the attacker to execute further system commands without needing any additional execution rights. The flaw does not require user interaction, meaning a malicious application or a compromised component could exploit it autonomously.
Affected Systems
The affected product is Google Android. No specific version range is listed in the CNA data; therefore, devices running any Android revision prior to the fix that includes the updated openLogicalChannel implementation are potentially vulnerable. The vulnerability is present in multiple source files, indicating a widespread change across the Android platform.
Risk and Exploitability
The CVSS score of 7.8 reflects a moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that known exploitation activity is not reported at this time. The vulnerability is local, meaning executable code does not need to be injected, and no additional privileges are needed beyond the user who can invoke the vulnerable function. Exploitation is likely feasible in environments where a malicious application can access logical channel APIs or where device management delegates such capabilities to untrusted components.
OpenCVE Enrichment