Impact
A logic error in the Android Cellular Modem component can reveal sensitive information and, more critically, allows an attacker to execute arbitrary code on the device without requiring additional privileges. The flaw is exploitable without any user interaction, meaning that a malicious actor can trigger the attack directly through the modem interface.
Affected Systems
The issue affects Android devices that incorporate the cellular modem stack as defined by Google. No specific device models or operating system versions are listed, so all Android releases where this software component is present are potentially impacted.
Risk and Exploitability
The high CVSS score of 8.8 reflects severe impact and lack of mitigations in the current code. The EPSS score of <1% indicates a very low, but non‑zero, probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, the absence of user interaction and the ability to execute code remotely indicates that exploitation is plausible. Organizations should treat this as a high‑risk threat pending an official fix.
OpenCVE Enrichment