Impact
The vulnerability is a use‑after‑free logic error that permits a remote attacker to elevate their privileges on an affected Android device. The flaw does not require any additional execution privileges or user interaction; a network‑reachable attacker could trigger it to gain higher privilege levels.
Affected Systems
All Android devices that include the affected code paths are potentially impacted. The CNA lists the product as Google:Android. No version or specific module information is supplied, so the risk applies broadly across all Android install base until a patch is released.
Risk and Exploitability
The EPSS score is low (< 1%) and the vulnerability is not listed in CISA’s KEV catalog. A CVSS score of 9.8 indicates a critical level of severity, and the described remote privilege escalation without user interaction highlights a high risk. The attacker can potentially gain system level privileges over the network, making the vulnerability a critical threat until a vendor patch is deployed.
OpenCVE Enrichment