Impact
An out-of-bounds write can occur in multiple parts of the system due to a missing bounds check. This flaw may allow a local attacker to gain system-level privileges without needing any user interaction. The nature of the vulnerability is a buffer overrun (CWE-787).
Affected Systems
The flaw affects Android devices provided by Google. No specific kernel or Android version information is listed in the available data.
Risk and Exploitability
The CVSS score of 6.7 indicates a medium severity vulnerability. The EPSS score is 0.00075 (less than 1%), indicating a very low probability of exploitation. The flaw can be exploited locally by a malicious user or compromised app without any user interaction. The vulnerability is not listed in the CISA KEV catalog, so there is currently no evidence of active exploitation. Given the local context and requirement for system privileges, an attacker who gains local access can elevate privileges to execute arbitrary code.
OpenCVE Enrichment