Impact
A logic error in acfw_ resulting system‑level execution privileges and does not need any user interaction to be exploited.
Affected Systems
The flaw affects Google Android devices; specific impacted builds are not listed, but the associated security bulletin points to a Pixel release from September 2026.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity. The EPSS score is < 1%, and the issue is not listed in the CISA KEV catalog. Exploitation requires local system privileges, so a malicious actor must already have the ability to execute code with system‑level rights to read sensitive information.
OpenCVE Enrichment