Impact
The vulnerability is an authentication bypass in the IP Multimedia Subsystem that allows an attacker to elevate privileges without gaining additional execution privileges. This flaw can enable remote perform actions typically restricted to higher privilege levels. The weakness results from improper authentication handling and falls under authentication and authorization categories.
Affected Systems
The issue affects Google Android devices. No specific Android OS version numbers are provided, so all variants that incorporate the affected IP Multimedia Subsystem code are potentially vulnerable.
Risk and Exploitability
The risk is high because the flaw permits remote privilege escalation with no user interaction. No CVSS score is available in the CVE record; however, the absence of a public EPSS score and lack of listing in the CISA KEV catalog indicate that exploitation may not yet be widespread or publicly documented. The likely attack vector is a remote network or over‑the‑air connection, inferred from the requirement that no user interaction is needed for exploitation, and attackers could exploit this logic flaw in the authentication routine.
OpenCVE Enrichment