Impact
The vulnerability is a permission bypass in DreamPickerReceiver.kt that allows a confused deputy to grant an app System execution privileges. An attacker with local device access can run privileged code without any user interaction.
Affected Systems
Google Android OS. No specific versions are identified in the advisory.
Risk and Exploitability
The CVSS score is 6.7, indicating medium severity. The EPSS score is less than 1%, suggesting a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires no user interaction and is fully local, making it attractive for attackers but the low EPSS indicates it is not widely exploited at present.
OpenCVE Enrichment