Impact
A logic error in the hwcrypto-kdn.c function kdn_set_sysregs_prot permits local information disclosure when system execution privileges are available. The bug exposes sensitive data to any code running with system-level access. This is an information leakage flaw consistent with CWE-200.
Affected Systems
The vulnerability affects Android devices from Google. No specific product names or versions are listed beyond the general Android platform, and no fine‑grained version details are available.
Risk and Exploitability
User interaction is not required, and exploitation is feasible from any code that already has system privileges. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known active exploits at the time of this analysis. However, the absence of an exploit does not negate the potential impact for privileged malware or malicious users within the device. The CVSS score is not specified, so the overall risk should be assessed based on the known privilege requirements and leakage severity.
OpenCVE Enrichment