Impact
The vulnerability resides in the bigo_worker_thread function of the bigo.c module. The race condition allows a local process to manipulate execution flow, potentially elevating its privileges to system-level execution rights. An attacker can gain full control over the affected device without requiring any user interaction, thereby compromising confidentiality, integrity, and availability.
Affected Systems
This issue affects the Android operating system on Google devices. The specific component impacted is the Bigo service within the system, and it is not tied to a particular Android version, suggesting that any device running the affected build of the Bigo service is vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score is less than 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the race condition does not demand user interaction, a local attacker or one with physical access could trigger it autonomously and elevate privileges to system level. Any local attacker can exploit this flaw, as it does not require prior specialized privileges.
OpenCVE Enrichment