Impact
The vulnerability is a permission bypass caused by a confused deputy across multiple Android source files. It permits a local attacker to gain system execution privileges without requiring user interaction. Based on the description it is inferred that the flaw allows escalation from ordinary user level to full system control, compromising all data and functions on the device.
Affected Systems
Google Android operating system devices are affected. No specific version numbers are listed, but based on the CNA vendor information it is inferred that the flaw exists in multiple Android source files across the platform. All devices running the affected codebase until patched are at risk.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity. The EPSS score is < 1%, meaning the probability of exploitation is very low, and it is not cataloged in the CISA KEV. Based on the description it is inferred that the vulnerability can be exploited locally without user interaction, so any compromised or malicious app could trigger the privilege escalation to system level.
OpenCVE Enrichment