Impact
FsmReleaseKey in fsm.c contains an input‑validation flaw that permits a caller to bypass permission checks. The flaw is an improper validation of data (CWE‑20), allowing an attacker with local device access to elevate privileges without any additional execution rights or user interaction.
Affected Systems
The issue affects Google’s Android operating system. No specific Android releases are disclosed, so any device running Android with the vulnerable FsmReleaseKey implementation is potentially impacted. The flaw resides in the core system, not in a particular app.
Risk and Exploitability
The CVSS score of 8.4 indicates a high‑severity vulnerability. The EPSS score of less than 1% suggests a very low probability of widespread exploitation at present. The flaw is purely local; no remote attack vector exists and it is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker who can run code on the device can exploit the flaw to gain elevated privileges immediately, with no need for user interaction.
OpenCVE Enrichment