Impact
Android has a logic error that allows a permission bypass in multiple code paths. An attacker with user‑level execution privileges can use this flaw to gain higher privileges on the device, potentially enabling the modification of system files or execution of privileged code. This type of vulnerability enables an attacker to compromise confidentiality, integrity, and availability of the affected device without relying on third‑party input or malicious user interaction.
Affected Systems
The vulnerability applies to Android devices sold by Google, including Pixel phones. The specific affected Android releases are not listed, but the issue exists in the current Android code base as of the latest security bulletin.
Risk and Exploitability
The CVE is not listed in the CISA KEV catalog and no EPSS score is available, so the exploitation probability is currently unknown. Exploitation requires local device access and user execution privileges but does not need user interaction, meaning an attacker could potentially elevate privileges automatically after gaining a foothold. The severity of this local privilege escalation warrants timely remediation.
OpenCVE Enrichment