Impact
In the validate_ns_buf function of mbu_class.rs, an improper input validation allows an attacker to read sensitive data. The vulnerability can result in local information disclosure and requires system‑execution privileges. An attacker does not need to perform any user interaction to exploit it. The impact is thus limited to the scope of the user or process with those privileges. The weakness is classified as CWE‑20.
Affected Systems
The affected product is Google Android. No specific version or additional vendor information is provided, so all Android devices using the affected code path are at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 4.4 indicates a low to medium severity. The EPSS score of 0.00073 (<1%) indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it has not yet been actively exploited in the wild. Exploitation requires local system‑execution privileges and does not rely on user interaction, so an attacker with sufficient local access can read protected data. The risk remains moderate because it does not enable remote code execution or compromise larger system integrity.
OpenCVE Enrichment