Impact
The vulnerability is a missing bounds check in the function gmc_phy_lp3_exit_restore_registers of phy_power.c. This omission can allow a local attacker to modify hardware registers in a way that grants System execution privileges. Because no user interaction is required, an attacker need only be able to run code on the device to exploit the flaw, leading to full local privilege escalation.
Affected Systems
Google Android devices that implement the affected gmc_phy_lp3_exit_restore_registers function are susceptible. No specific Android version or device family is listed, so all releases containing the vulnerable code may be impacted until patched.
Risk and Exploitability
The EPSS score is unavailable and the flaw is not listed in CISA’s KEV catalog, but the CVSS severity is implicitly high given the local escalation and no user interaction requirement. Attacks would likely proceed from a malicious local program that gains a foothold on the device, then manipulates the registers to achieve privileged execution. The absence of an external trigger or network component limits the attack to devices directly compromised by local code execution.
OpenCVE Enrichment