Impact
An out-of-bounds write can occur in Av1DecodeFrameTag within vp9hwd_headers.cc. The missing bounds check allows an attacker to overwrite adjacent memory, potentially enabling remote escalation of privilege. This flaw does it can be exploited remotely or locally over a network channel.
Affected Systems
Google Android devices are affected, particularly versions that include the vulnerable vp9hwd_headers.cc source as referenced in the Google security bulletin. No specific minor revisions are listed, so all Android builds containing the unpatched source code are potentially vulnerable.
Risk and Exploitability
The CVSS score is 8.8, indicating a high severity vulnerability. The EPSS score is less than 1%, indicating a low probability of exploitation at this time, but the lack of required user interaction and remote privilege escalation capability mean the flaw could still be a valuable target for attackers. The vulnerability is not currently listed in CISA’s KEV catalog.
OpenCVE Enrichment