Impact
The vulnerability originates from a logic error in the Android operating system that allows a local user to obtain system execution privileges. The code flaw is exploitable without any user interaction, meaning any user with physical or local access to the device can trigger it. The description does not mention any impact on confidentiality, integrity, or availability beyond the privilege escalation itself.
Affected Systems
Android running on Google‑manufactured devices, such as Pixel smartphones and tablets, are affected. No specific Android build or OS version is listed, so all current releases may contain the flaw until it is addressed by a security update.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity. With a very low EPSS score of <1% and no listing in the CISA KEV catalog, no exploitation has been documented. The flaw requires only local access and no user interaction, so any user with physical or local device access could exploit it to elevate to system privileges. Public exploitation remains unknown, yet the risk is significant for users possessing local access.
OpenCVE Enrichment