Impact
In the FsmReleaseKey function within fsm.c, a flaw allows an application to bypass permission checks because input is not properly validated. As a result, an attacker can gain higher privileges on the device with the user. The weakness can be classified as an improper input validation vulnerability that permits a permission bypass, potentially exposing the system to unauthorized actions.
Affected Systems
This vulnerability affects Google's Android operating system. Specific affected Android versions are not disclosed in the CVE data, so any installation of Android that includes the FsmReleaseKey implementation could be vulnerable. The weakness lies in the system-level handling of this function rather than in a particular application.
Risk and Exploitability
The vulnerability is local and requires no special user interaction; an attacker with access to the device can exploit it. The exploit does not rely on remote code execution but exploits local privilege escalation. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, however the severity of the impact suggests a high-level risk if present. The likely attack vector is a local attacker or malware on the device that can call the vulnerable function.
OpenCVE Enrichment