Impact
The vulnerability lies in the get_global_config_item_addr function of Android's gc.c module, where a missing bounds check allows an out‑of‑bounds read. Exploitation of this flaw can be performed by a local user without prior elevated rights, enabling access to privileged data and subsequent elevation of privileges. Because no additional execution privileges are required, the attack does not need arbitrary code execution, yet it compromises system integrity and confidentiality for the affected device.
Affected Systems
Android operating systems supplied by Google are impacted. No specific version numbers are listed in the advisory, so any device running a build that contains the unpatched gc.c code may be vulnerable.
Risk and Exploitability
Exploitation is local and does not require user interaction, making the attack vector straightforward. EPSS data is not available and the issue is not listed in CISA KEV, indicating that no public exploits have been documented at the time of this analysis. Nonetheless, the ability for a local user to gain elevation of privilege with minimal prerequisites places the risk in the high category for any affected device.
OpenCVE Enrichment