Impact
An out‑of‑bounds write in the Video Processing Unit (VPU) caused by a confused‑deputy condition allows an attacker to gain higher privileges on the device without acquiring additional execution rights. The flaw resides in a memory corruption vulnerability (CWE‑787) that is triggered by a mis‑handled authority escalation (CWE‑441). This could enable a local user to execute code or modify system state beyond their normal rights, effectively compromising the integrity of the device.
Affected Systems
The vulnerability applies to Android devices that include the VPU component, as identified by the vendor Google:Android. No specific device model, Android version, or firmware release has been documented in the available data, so any device containing the VPU and lacking the informed security patch could be affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity flaw. The EPSS score of < 1% shows that the likelihood of exploitation is very low but not zero. The flaw can be exploited locally without requiring user interaction, which lowers the practical barrier for an attacker. The vulnerability is not listed in the CISA KEV catalog, but the combination of high severity and ability to elevate local privileges warrants prompt attention.
OpenCVE Enrichment