Impact
The vulnerability lies in a logic error within the GPU component of the Android operating system. It permits a local attacker to bypass permission checks, which can lead to the execution of code with system privileges. This flaw is classified as CWE-693 and does not require remote interaction or user involvement, so any user with access to the device may exploit it.
Affected Systems
The flaw affects Google Android devices. Specific affected OS versions are not listed in the advisory; however, the security bulletin linked provides details for the latest patch cycle available at the time. Users should check the release notes for their device model to confirm whether the GPU code in their Android version incorporates the fix.
Risk and Exploitability
The CVSS score is 6.7, indicating a moderate risk. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA KEV. Exploitation is local only, requiring the attacker to have physical or local access to the device, and does not need user interaction. As a result, the risk is significant for users who have screen access to the device or who leave it unlocked, but is less relevant for remote or unattended scenarios.
OpenCVE Enrichment