Impact
The vulnerability is an out‑of‑bounds write in several functions of remap.c caused by an incorrect bounds check. This flaw can allow an attacker to overwrite memory locations on the device, potentially granting local System execution privileges. No user interaction is required for exploitation, meaning an attacker who can run code locally on the device can abuse the issue to elevate privileges.
Affected Systems
The affected products are Google Android devices. No specific Android versions are listed in the advisory, but any device that has not yet applied the latest security update referenced by the Google bulletin would be vulnerable.
Risk and Exploitability
With a CVSS score of 6.7, the vulnerability is moderate in severity. The EPSS score of 0.00075 (well below 1%) indicates a very low probability of exploitation, and it is not listed in the CISA KEV catalog. No user interaction is required, making the attack convenient for an attacker who has already compromised the device.
OpenCVE Enrichment