Impact
In Android’s libc, the printf implementation contains an out‑of‑bounds write caused by insufficient input validation. This flaw can overwrite adjacent memory and, when executed locally, allows an attacker to gain system execution privileges. The description states that user interaction is not needed for exploitation, indicating that the vulnerability is available to any local code that can supply crafted input.
Affected Systems
The affected customers are Google Android device users. The vendor information lists Google:Android, but the data does not specify which OS versions or build identifiers contain the flaw. In the absence of detailed versioning, administrators should assume that devices running recent Android releases may be impacted until a patch is confirmed.
Risk and Exploitability
The vulnerability has a CVSS score of 6.7, indicating moderate to high risk, while the EPSS score is below 1%, suggesting a low probability of widespread exploitation at the time of analysis. The CVE is not listed in CISA KEV, but the lack of a KEV flag does not diminish the need for remediation. The attack path is local, requiring only the ability to execute code that invokes printf with malformed arguments; no network or user‑interaction vector is described.
OpenCVE Enrichment