Impact
A missing permission check in the Android Setup Wizard allows an attacker to remotely install software packages. This flaw provides a direct path to elevate privileges without any user interaction or additional execution rights. The flaw has a CVSS score of 8.4, indicating a high severity. The impact is an immediate increase in attacker privileges on the device, potentially granting full control of the system.
Affected Systems
Google Android, specifically the Setup Wizard component. No version information is available in the current advisory, so any device running the affected Android release is at risk.
Risk and Exploitability
The vulnerability can be exploited remotely without user interaction, indicating a significant impact if exploited. However, the EPSS score of < 1% indicates a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Nonetheless, due to the severity of remote privilege escalation, devices should be updated promptly to prevent potential compromise.
OpenCVE Enrichment