Impact
A buffer overflow exists within the decodeAmr function of the Android media player, uncovered by a missing bounds check. This flaw allows an attacker to write beyond the intended memory area, potentially enabling execution of arbitrary code. The vulnerability is classified as a buffer copy without proper size validation, and the official assessment indicates that no additional privileges are required for exploitation.
Affected Systems
The flaw is present in the Android operating system supplied by Google. No specific OS versions or build variants are listed, so any Android installation that includes the current, unpatched media audio player code could be vulnerable until a patch is applied.
Risk and Exploitability
The assigned CVSS score of 8.0 reflects high exploitable risk, and the EPSS score of < 1% indicates a very low but nonzero probability that the vulnerability will be exploited. The weakness requires user interaction, likely through the playback of a crafted AMR media file, meaning that a malicious file needs to be opened or played by the user. Because it is not listed in the CISA KEV catalog, no public exploits are confirmed, but the high severity and need for ordinary user action suggest that the vulnerability could be leveraged in targeted attacks.
OpenCVE Enrichment