Impact
The vulnerability originates from uninitialized data in functions within physmem_extmem_linux.c, causing an out‑of‑bounds read. This flaw can expose sensitive memory contents to a local attacker without any required escalation of privileges, and no user interaction is needed for exploitation.
Affected Systems
Google Android devices that run kernel versions affected by the 2026‑09‑01 security bulletin.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity. With the EPSS score of < 1% and the vulnerability not listed in the CISA KEV catalog, the likelihood of exploitation is considered low, yet the risk remains a local information disclosure. Exploitation does not require elevated privileges or additional user interaction, but once triggered it can disclose local data from the device.
OpenCVE Enrichment