Impact
The vulnerability is a heap buffer overflow in the ihevcd_get_tu_data_size function of ihevcd_utils.c. Exploitation results in an out‑of‑bounds write that can elevate a local user’s privileges without granting additional execution privileges. The description states that no user interaction is required for exploitation, indicating that the attack is local and can be performed by any user with access to the affected component.
Affected Systems
The flaw exists in Google’s Android operating system. No specific Android releases are enumerated in the provided data, so all Android devices that include the implicated ih-e–VCD component could be affected.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as High severity. EPSS data is not available, and the vulnerability is not yet listed in the CISA KEV catalog. Because user interaction is not needed, a determined attacker with local access can exploit the buffer overflow to gain elevated privileges, potentially leading to full system compromise. The attack vector is inferred to be local, as no remote channel is described and the description explicitly notes that exploitation can occur without additional user action.
OpenCVE Enrichment