Impact
The vulnerability is a use-after-free logic error that permits a remote attacker to elevate their privileges on an affected Android device. The flaw does not require any additional execution privileges or user interaction; a network- reachable attacker could trigger it to gain higher privilege levels.
Affected Systems
All Android devices that include the affected code paths are potentially impacted. The CNA lists the product as Google:Android. No version or specific module information is supplied, so the risk applies broadly across all Android install base until a patch is released.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. No CVSS score is provided, but the described remote privilege escalation without user interaction indicates a high severity impact. The attacker can potentially gain system level privileges over the network, making the vulnerability a critical threat until a vendor patch is deployed.
OpenCVE Enrichment