Impact
An integer overflow in the VPU causes an out‑of‑bounds write, enabling a local attacker to gain higher privileges without requiring additional execution rights. The flaw falls under integer overflow and buffer overrun weaknesses (CWE-190 and CWE-787). The resulting privilege escalation could allow the attacker to modify system state, potentially compromising all data on the device.
Affected Systems
Google’s Android operating system is affected. No specific version range is given, but the flaw is identified in the Android VPU firmware that ships with current builds.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score is reported as < 1% (approximately 0.00073), indicating a very low but non‑zero exploitation probability. The issue is not listed in CISA KEV; however, the lack of an exploit requirement and the local nature of the attack mean that any authenticated user could exploit the flaw. The vulnerability is likely to be exploited on devices that have not applied the patch and where the VPU is reachable by user‑controllable code.
OpenCVE Enrichment