Impact
The flaw is a logic error in the Android Cellular Modem code that permits a device to bypass required permission checks. This flaw can be exploited to elevate privileges without additional execution rights, and no user interaction is required. An attacker can leverage this to run code with higher authority than intended. The primary weakness is a permission violation leading to privilege escalation.
Affected Systems
The issue affects Google Android devices that implement the Cellular Modem component. No specific product versions were listed, so any device using the affected code may be vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 8.8 signals high severity. The EPSS score is reported as less than 1%, suggesting current exploitation probability is low, but the issue is listed in the CISA KEV catalog, indicating confidence that it is materially exploitable. The likely attack vector is remote or proximal/adjacent, such as through the cellular network or from a nearby device, with no user interaction required. The exploit path relies on the logic error that circumvents permission validation within the modem driver.
OpenCVE Enrichment