Impact
A race condition in several Android components allows a use-after‑free that can be triggered locally. The flaw causes the system to execute code with system privileges, enabling an attacker to elevate any of their local processes.
Affected Systems
All Android devices that rely on the affected components are vulnerable, including Google Pixel phones and any devices running an unpatched Android version. The vulnerability is present in the core OS libraries where the race condition exists. No specific version ranges are listed, so all installations before the latest security patch may be at CVSS score of 7 indicates high severity, and the fault does not require user interaction or network access. Because the use-after‑free is local, an attacker must have physical or local access to the device. The lack of an EPSS score and KEV listing suggests no confirmed public exploits yet, but the high severity and the local privilege escalation potential warrant prompt patching.
Risk and Exploitability
The CVSS score of 7 reflects high severity, with a potential for full system compromise via local privilege escalation. No EPSS score is provided, and the vulnerability is not currently listed in the CISA KEV catalog, indicating that public exploits are not confirmed. The flaw can be exploited without user interaction or network access, but it requires local or physical access to the device. Attackers could trigger a race condition that results in a use‑after‑free, potentially running arbitrary code with system privileges. Given the high impact and the absence of known exploits, the risk is considered moderate‑high, and immediate patching is advised.
OpenCVE Enrichment