Impact
The vulnerability is a missing bounds check in the Wave6VpuDecFlush function of Android's Wave6 video decoder, which can lead to an out-of-bounds write. This flaw enables a local attacker to corrupt memory from a buffer overrun, potentially elevating privileges to that of a system or privileged application. The weakness is reflected by CWE identifiers 120 and 787.
Affected Systems
Android devices that implement Google’s Wave6 video decoding component are affected, including Pixel smartphones and other hardware that incorporates the unpatched Wave6 library. No explicit Android version or build number is listed, so any device containing the vulnerable component prior to a security patch is at risk.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity for local privilege escalation. The EPSS score of less than 1% suggests a low likelihood of public exploitation at present, and the vulnerability is not listed in CISA KEV. Because no user interaction is required and only local execution privileges are needed, the attack vector is local; however, the lack of exploitation evidence and the low EPSS score imply that immediate impact is limited but the high CVSS warrants prompt remediation.
OpenCVE Enrichment