Impact
An out‑of‑bounds write in the IP Multimedia Subsystem (IMS) on Android allows an attacker to execute arbitrary code on the affected device. The vulnerability stems from insufficient input validation, as indicated by CWE‑20 and CWE‑787. Because no additional execution privileges are required, the code can run with the privileges of the IMS service, potentially compromising the device’s confidentiality, integrity affected vendor is Google for its Android operating system. The flaw resides within the IMS component of Android; specific version details are not provided in the CVE entry.
Affected Systems
The affected system is the Android operating system from Google. No specific affected version information is listed in the CVE entry.
Risk and Exploitability
Security analysis gives this flaw a CVSS score of 8.8, reflecting a high‑severity risk. The EPSS score of < 1% indicates a very low probability that the vulnerability will be exploited. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting a lower likelihood of widespread exploitation at present. User interaction is not required, implying a remote attack potential that can be triggered from the network side of the IMS exposure.
OpenCVE Enrichment