Impact
A missing bounds check in the function that loads GNSS images causes an out‑of‑bounds write in Android’s link_device.c. The flaw can be and potentially gain SYSTEM privileges. This is a classic example of an out‑of‑bounds write (CWE‑787) that allows local privilege escalation without requiring user interaction.
Affected Systems
The vulnerability is present in Google Android devices that implement the link_load_gnss_image routine. No specific model or Android version is disclosed in the available data, so this function should be considered at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, and the flaw is local in nature with no user interaction needed. The EPSS score is <1% and the issue is not listed in the CISA KEV catalog, but the lack of a publicly known exploit does not reduce the risk of a local attacker using the flaw. a notable risk for devices that remain unpatched.
OpenCVE Enrichment