Impact
A use‑after‑free bug triggered by a race condition can be exploited on Android devices to elevate a local attacker’s privileges. The flaw allows memory corruption that, when triggered, can execute code with system privileges. Based on the description, it is inferred that the attack requires standard user‑level privileges to launch the race, and no user interaction is needed.
Affected Systems
Android operating systems on Google devices are affected. No specific version information is provided, so the official fix has been released for all Android releases.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate risk for local attackers. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. Exploitation is possible without user interaction, making the attack vector local. Based on the description, it is inferred that malicious applications or any code capable of influencing scheduler behavior could trigger the flaw.
OpenCVE Enrichment