Impact
The vulnerability is an authentication bypass in the IP Multimedia Subsystem that allows an attacker to elevate privileges without gaining additional execution privileges. This flaw can enable higher privilege levels. The weakness results from improper authentication handling and falls under authentication and authorization categories.
Affected Systems
The issue affects Google Android devices. No specific Android OS version numbers are provided, so all variants that incorporate the affected IP Multimedia Subsystem code are potentially vulnerable.
Risk and Exploitability
The risk is high because the flaw permits remote privilege escalation with no user interaction. The CVSS score of 9.8 indicates critical severity, while the EPSS score of < 1% indicates a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. The likely attack vector is a remote network or over‑the‑air connection, inferred from the requirement that no user interaction is needed for exploitation, and attackers could exploit this logic flaw in the authentication routine.
OpenCVE Enrichment