Impact
A use‑after‑free bug triggered by a race condition can be exploited on Android devices to elevate a local attacker’s privileges. The flaw allows memory corruption that, when triggered, can execute code with system privileges. The attack requires standard user‑level privileges to launch the race, and no user interaction is needed.
Affected Systems
Android operating systems on Google devices are affected. No specific version information is provided, so all Android releases deployed on Google hardware remain potentially vulnerable until an official fix is released.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate risk for local attackers. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. Exploitation is possible without user interaction, making the attack vector local. The presence of a race condition and use‑after‑free suggests that malicious applications or any code capable of influencing scheduler behavior could trigger the flaw.
OpenCVE Enrichment