Impact
The vulnerability arises from an out‑of‑bounds write in the AudioRtpPayloadEncoderNode component of Android, caused AudioRtpPayloadEncoderNode.cpp. The flaw can allow an attacker to tamper with memory and cause An attacker can gain this capability without escalating privileges, and the impact includes full compromise of the affected device. The weakness aligns with input validation mistakes and unsafe memory operations.
Affected Systems
The flaw affects Google Android devices. Version information is not specified, so all Android releases that include the affected code path are potentially vulnerable until they receive the official patch. The risk applies to any Android device that processes audio RTP streams with this encoder.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score of < 1% suggests that the probability of exploitation in the wild is low. The vulnerability is listed as not being in the CISA KEV catalog, so there is no evidence of public exploitation. The likely attack vector requires user interaction; an attacker would need a user to engage with a malicious audio source or application that uses the vulnerable encoder. Once executed, the attacker can run code with the privileges of the current application without additional privilege escalation.
OpenCVE Enrichment