Impact
A memory corruption flaw in the Video Processing Unit (VPU) allows an attacker to perform an out‑of‑bounds write based on a confused‑deputy scenario. This bug can upgrade the privileges of a local user without any further execution privileges and does not require user interaction. The result is effectively a local escalation of privilege capable of compromising device integrity. The weakness is a mix of out‑of‑bounds write (CWE‑787) and a confused deputy condition (CWE‑441).
Affected Systems
Android devices that include the VPU component, primarily Google Pixel smartphones. No specific model or Android version is mentioned in the data, so any device with a VPU that has not yet received the security patch is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the attacker can exercise this flaw locally without special conditions. The EPSS score of < 1% indicates a very low, yet non-zero, likelihood of exploitation, which combined with the lack of user interaction requirement suggests a relatively low barrier to successful attacks. The vulnerability is not listed in CISA’s KEV catalogue, but the severity and local nature make it a prime candidate for immediate remediation.
OpenCVE Enrichment