Impact
A race condition exists in multiple locations within the Android system where a check is performed on a resource and the resource is used before the check can finish, creating a time‑of‑check to time‑of‑use flaw. This flaw can allow a local attacker to execute code with system‑level privileges. The affected component grants System execution rights, so exploitation could compromise the entire device, allowing the attacker to install malware, exfiltrate data, or modify system settings, thereby impacting confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Google Android devices, with Google identified as the CNA. All Android systems containing the unpatched race condition are considered at risk.
Risk and Exploitability
The CVSS score of 6.7 indicates a medium-to-high risk severity. The EPSS score is <1% and the vulnerability is not listed in the KEV catalog, suggesting that it is not yet widely exploited, but local exploitation does not require user interaction. The attack can be carried out from a local user context, so any device user or local process can trigger it. Given the potential for full system compromise, the risk warrants timely remediation.
OpenCVE Enrichment