Impact
The vulnerability lies in the get_global_config_item_addr function of Android's gc.c module, where a missing bounds check allows an out‑of‑bounds read. This out‑of‑bounds read is a classic buffer overread flaw (CWE‑125) and can be seen as a buffer overflow scenario (CWE‑120) that can be leveraged to read privileged data and elevate privileges locally. Exploitation of this flaw can be performed by a local user without prior elevated rights, enabling access to privileged data and subsequent elevation of privileges. Because no additional execution privileges are required, the attack does not need arbitrary code execution, yet it compromises system integrity and confidentiality for the affected device.
Affected Systems
Android operating systems supplied by Google are impacted. No specific version numbers are listed in the advisory, so any device running a build that contains the unpatched gc.c code may be vulnerable.
Risk and Exploitability
Exploitation is local and does not require user interaction, making the attack vector straightforward. The CVSS score of 8.4 classifies the flaw as High, indicating a significant impact on device confidentiality, integrity, and availability. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV, suggesting that no public exploits are currently known. Nevertheless, the ability for a local user to gain elevation with minimal prerequisites places the risk in the device, warranting immediate attention.
OpenCVE Enrichment