Impact
The flaw is a type‑confusion bug found in several source files on Android devices. When triggered, it permits a local attacker to read cryptographic signatures that should be protected, effectively escalating privileges on the device. The adversary gains higher system rights without needing to run additional code or exploit user interaction, allowing further exploitation or data compromise.
Affected Systems
Google’s Android operating system is affected. No precise version numbers are listed, so any Android installation containing the vulnerable modules may be at risk.
Risk and Exploitability
The CVSS score of 8.4 indicates a high‑severity vulnerability, while the EPSS score is less than 1%, suggesting a low current exploitation probability. The issue is not included in CISA’s KEV catalog. The attack vector is local; the vulnerability can be triggered by a malicious application already installed on the device, and it does not require user interaction.
OpenCVE Enrichment