Impact
The vulnerability is an out‑of‑bounds write that occurs due to a race condition in the google_mba_recv_msg function of google_mba_poll.c. It exploits CWE‑362 (Concurrent Execution: Race Condition) and CWE‑787 (Out‑of‑Bounds Write) to corrupt memory. The corrupted memory can provide the attacker with local privilege escalation, without needing any additional execution privileges or user interaction.
Affected Systems
The flaw affects Google’s Android operating system. No specific product version is supplied, so any Android device that incorporates the affected google_mba_poll component is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.0 indicates moderate severity. The EPSS score of 0.00054 indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, but the attack vector is local and requires no user interaction. Once an attacker has local access is straightforward, potentially granting higher privileges.
OpenCVE Enrichment