Impact
A flaw in the Trusted Execution Environment of Android permits improper input validation (CWE‑20) and memory corruption (CWE‑788) that can corrupt memory, allowing an attacker with local access to obtain system execution privileges. The description indicates that no user interaction is required for exploitation, meaning an attacker can trigger the corruption and elevate privileges solely through local access.
Affected Systems
The vulnerability affects Android devices from Google. No specific version numbers are provided, so any device running Android with a Trusted Execution Environment is potentially impacted until an official fix is released.
Risk and Exploitability
The exploit requires local access and can give an attacker system execution privileges, potentially enabling full system compromise. The CVSS score of 6.7 classifies it as moderate severity. EPSS indicates a very low probability of exploitation (<1%). The vulnerability is not cataloged in the CISA KEV list, and no remote attack vector is noted. These indicators together imply that the risk is mainly constrained to local contexts, but the potential impact is substantial should exploitation occur.
OpenCVE Enrichment