Impact
The vulnerability originates from a logic error in the Android operating system that allows a local user to obtain system execution privileges. The code flaw is exploitable without any user interaction, meaning any user with physical or local access to the device can trigger it. The description does not mention any impact on confidentiality, integrity, or availability beyond the privilege escalation itself.
Affected Systems
Android running on Google‑manufactured devices, such as Pixel smartphones and tablets, are affected. No specific Android build or OS version is listed, so all current releases may contain the flaw until it is addressed by a security update.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no documented exploitation at this time. Because the attack requires only local access and no user interaction, an attacker with physical or local access to the device could exploit the flaw to gain elevated system privileges. Public exploitation remains unknown, but the risk of privilege escalation remains significant for any user with local device access.
OpenCVE Enrichment