Impact
In the s_decode_vui_param function of fw_hevc_dec_header.c, a logic error allows an out-of-bounds write. This flaw can be exploited to achieve remote code execution without privilege escalation, and no user interaction is required.
Affected Systems
The vulnerability affects the Android operating system developed by Google. No specific Android version or build information is provided in the advisory, so all current Android releases are potentially impacted until a patch is issued.
Risk and Exploitability
With a CVSS score of 8.8, this flaw is considered high severity. The EPSS score is < 1%, but the lack of a listed KEV indicates it is not currently known to be widely exploited; however, exploitation could be achieved by supplying malicious HEVC-encoded content, making the attack vector remote. The flaw provides an avenue for attackers to execute arbitrary code on the device, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment