Impact
The vulnerability is a missing permission check in the fsm.c component’s FsmReleaseKey function on Android devices, which allows a local attacker to invoke system-level operations without being prompted for user interaction. The flaw enables elevation to system execution privileges, potentially granting full control over the device. The weakness is classified as CWE-693, reflecting a failure to enforce permissions.
Affected Systems
The affected product is Google in the advisory, so all installations of Android that include the vulnerable fsm.c code may be impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate severity. The EPSS score of 0.00079 (<1%) indicates a very low probability of exploitation at the time of this analysis, but the flaw can be triggered without user interaction, which increases the practical risk for any user with local access. The vulnerability is not currently listed in the CISA KEV catalog. Attackers with local access could exploit the permission bypass to gain system privileges and compromise integrity and confidentiality of the device.
OpenCVE Enrichment