Impact
The vulnerability is a defect in Android where uninitialized memory can be read in several code paths, allowing an attacker to gain access to sensitive data that should be hidden. The flaw is governed by CWE-457, which denotes use of uninitialized variables. Because some keys or user data can be exposed, the primary impact is the disclosure of local information, potentially compromising confidentiality of device contents. This is not a remote code execution flaw but can result in privacy loss for the device owner.
Affected Systems
The affected products are Android operating included in the product line referenced by the source link. No specific version range is listed in the provided CNA information, so any Android build that contains the vulnerable code paths could be impacted. Users of devices that be at risk.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity. The EPSS indicating a very low exploitation Coitation requires local system execution privileges, meaning an attacker must already device. User interaction is not needed, so a malicious app with sufficient privilege could trigger the flaw. The lack of remote code execution reduces the overall threat but the potential for sensitive data leakage remains significant.
OpenCVE Enrichment