Impact
A buffer over-read occurs in the function gf_algo_get_cached_dump_data within gf_algo.c because a bounds check is missing. This flaw is classified as a CWE‑125 "Out‑of‑Bounds Read" and can potentially expose sensitive information that the executing process can read from adjacent memory. The vulnerability does not provide remote code execution or privilege escalation, but it does allow a local attacker to obtain data that should be restricted.
Affected Systems
The affected product is the Android operating system distributed by Google. No specific version range is listed in the advisory, so all releases that include the vulnerable software component may be impacted until a patch is issued.
Risk and Exploitability
The CVSS base score of 5.5 indicates a moderate severity, and the EPSS score is low, <1%, indicating a very low probability of exploitation. The flaw requires local access to the device and does not need any special user interaction or execution privileges. The vulnerability is not included in the CISA KEV catalog, suggesting no known public exploitation at the moment. Attackers with physical or local device access could trigger the out‑of‑bounds read to extract confidential data from memory.
OpenCVE Enrichment