Impact
A logic error in Android code creates a possible permission bypass that can be exploited to acquire system execution privileges. The flaw allows an attacker to elevate local privileges without requiring user interaction, enabling them to perform actions for which the device normally lacks permission.
Affected Systems
The vulnerability is reported for Google Android devices. No specific version information is provided, so the issue potentially affects all Android releases that contain the affected code paths.
Risk and Exploitability
The EPSS score of 0.00126 (less than 1%) and the fact that the vulnerability is not listed in CISA KEV indicate a low probability of exploitation. Nevertheless, the local privilege escalation nature still poses significant risk if a device is compromised. An attacker with local access can exploit the logic error directly, bypassing permission checks to gain system-level capabilities. No.
OpenCVE Enrichment