Impact
The vulnerability is a use‑after‑free race condition that can lead to remote code execution without requiring additional privileges or user interaction. The flaw stems from improper synchronization and deallocating memory that may still be in use, allowing an attacker’s process rights, potentially compromising confidentiality, integrity, and availability in Android applications.
Affected Systems
The affected systems are Google Android devices. No specific affected version information is provided, so the flaw may be present across multiple Android releases until mitigated by an official security update.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score of less than 1% shows a very low but non‑zero exploitation probability. User interaction is not needed for exploitation, and the vulnerability can be triggered by any code running on the device or by network‑initiated actions. The entry is not listed in CISA’s KEV catalog, but the high CVSS score warrants urgent attention.
OpenCVE Enrichment