Impact
The vulnerability permits a local privilege escalation by bypassing permissions through side‑channel information disclosure. No additional execution privileges are required, and the attacker can achieve higher privileges on the device without executing arbitrary code. The flaw stems from an improper handling of sensitive data, causing the system to incorrectly grant elevated access rights.
Affected Systems
The affected platform is Google Android. Specific product names or version numbers are not listed in the CVE entry. The issue appears to apply broadly to Android devices, likely those shipping with the current security updates documented by Google. No narrow version scope is given.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity; exploitation does not require user interaction and can occur from any process on the device, making the risk notable for local attackers. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating it is not actively exploited in the wild. The lack of user interaction lowers the barrier for attackers who already have local access.
OpenCVE Enrichment