Impact
The vulnerability is a missing bounds check in the function gmc_phy_lp3_exit_restore_registers, which is defined in phy_power.c. This omission can allow a local attacker to modify hardware registers and gain System execution privileges, with no user interaction required.
Affected Systems
Google Android devices that implement the affected gmc_phy_lp3_exit_restore_registers function are susceptible. No specific Android version or device containing the vulnerable code may be impacted until patched.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low exploitation probability, and the CVSS score of 7.8 reflects significant local privilege escalation potential. The flaw is not listed in CISA’s KEV catalog. An attacker would likely proceed from a malicious local program that gains a foothold on the device, then manipulate the registers to achieve privileged execution. The absence of an external trigger or network component limits the attack to devices directly compromised by local code execution.
OpenCVE Enrichment