Impact
A permission bypass flaw in CPM results from a confused deputy scenario. An attacker can gain System execution privileges without user interaction, allowing local code execution at a higher privilege level. The weakness maps to the Confused Deputy vulnerability class, highlighting improper handling of authority boundaries within the component.
Affected Systems
The vulnerability affects Google Android devices that include the CPM component. Exact product and version details are not specified, but it applies to all devices running the affected CPM implementation at the time of disclosure.
Risk and Exploitability
With a CVSS score of 6.7, the flaw is considered medium severity. The EPSS score is very low (<1%) but not zero, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires only local access and does not need user interaction, making the attack surface convenient for privileged local adversaries.
OpenCVE Enrichment