Impact
This vulnerability is caused by an out-of-bounds write in the IP Multimedia Subsystem due to an incorrect bounds check. The flaw allows an attacker to execute arbitrary code on the device without needing additional privileges, and no user interaction is required. The weakness is a classic memory corruption error (CWE‑120).
Affected Systems
Android devices run by Google are affected. The flaw exists in the IP Multimedia Subsystem component, but specific Android OS or firmware versions are not the IMS stack are potentially vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the lack of a required user interaction means the attack can be carried out remotely over the IMS protocols. EPSS score of < 1% indicates a very low but non‑zero probability of exploitation, and the vulnerability is not listed in KEV, which suggests it may not have observed exploitation yet. An attacker can craft malformed IMS messages that trigger the out-of-bounds write, yielding remote code execution on the device.
OpenCVE Enrichment