Impact
This vulnerability in the Android Modem component allows an attacker to read sensitive data through improper input handling. The flaw results in a remote information disclosure; no additional execution privileges are required and no user interaction is necessary. The weakness is a classic input validation error, identified as CWE‑20.
Affected Systems
Google Android devices that include the Modem subsystem are impacted. Specific affected firmware or build versions have not been disclosed, so all current Android releases may be vulnerable until a patch is issued.
Risk and Exploitability
With a CVSS score of 7.5 the risk is high. Because the flaw can be triggered remotely and does not need user interaction, an attacker could potentially harvest confidential modem data from a victim device. The EPSS score is less than 1%, indicating a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, yet the exposure of sensitive data warrants prompt attention.
OpenCVE Enrichment