Impact
A missing permission check in the Android Setup Wizard allows an attacker to remotely install software packages. This flaw provides a direct path to elevate privileges without any user interaction or additional execution rights. The impact is an immediate increase in attacker privileges on the device, potentially granting full control of the system.
Affected Systems
Google Android, specifically the Setup Wizard component. No version information is available in the current advisory, so any device running the affected Android release is at risk.
Risk and Exploitability
The vulnerability can be exploited remotely and does not require user action, indicating a high exploitation likelihood. Although the EPSS score is not available and the flaw is not listed in the CISA KEV catalog, the severity of remote privilege escalation and lack of mitigation steps make the risk of exploitation substantial. Affected devices should be updated promptly to prevent potential compromise.
OpenCVE Enrichment