Impact
The Android VPU software contains a defect that allows a program to overwrite shared memory used by privileged system components. The flaw arises because the VPU does not properly validate input data when reading from shared memory, enabling an attacker to write arbitrary data to memory that is later used for privileged operations. Once the overwrite occurs, the attacker can gain higher privilege levels within the device and potentially execute code with system privileges. This vulnerability requires no user interaction and therefore can be exploited autonomously from a local context.
Affected Systems
Android devices manufactured by Google, including any Android implementation that includes the VPU component. Exact version information is not provided, so all Android devices with the VPU are potentially impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 6.7, indicating a medium severity. The EPSS score is <1%, suggesting an unlikely exploitation probability at present. The flaw is not listed in the CISA KEV catalog. Attackers would need local access to the device, but no user interaction is required. While the risk is moderate, devices that run untrusted code could be compromised if the VPU is accessed by malicious applications.
OpenCVE Enrichment