Impact
The vulnerability arises from a missing bounds check in the setTo function of ResourceTypes.cpp, permitting an out‑of‑bounds heap read. An attacker can read arbitrary memory contents stored on the device, potentially exposing confidential data. No elevated privileges or additional execution rights are required, and a user does not need to interact with the system to exploit the flaw.
Affected Systems
The affected product is Google Android operating systems. Specific version information is not provided in the source data, so all Android installations that include the unpatched ResourceTypes.cpp code are potentially impacted.
Risk and Exploitability
The CVSS score is 3.3. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is listed as not being part of the CISA KEV catalog. Because the flaw can be triggered from a local context without user interaction, the risk level is low for devices exposed to untrusted applications or data. An attacker with local access could read sensitive data, and the lack of a privilege escalation vector limits the scope to local data exposure only. The likely exploit path would involve a malicious application or a script executing within the device’s user context that calls the vulnerable setTo method. The attack vector is inferred to be local, as no network or remote execution is required.
OpenCVE Enrichment