Impact
The vulnerability arises from improper casting in multiple functions of ftsmooth.c, resulting in a memory safety issue that can lead to remote code execution without requiring elevated privileges. The weakness is a type‑mismatch error, classified as CWE‑704, and can be triggered without user interaction.
Affected Systems
The affected product is the Android operating system produced by Google. No specific Android version numbers are listed in the available data, so all releases that include ftsmooth.c may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. Although the EPSS score is not provided, the exploit can be performed remotely, requires no privilege escalation, and does not need user interaction. The vulnerability is not yet listed in the CISA KEV catalog. Attackers could target the flaw by invoking the affected component through any vector that triggers ftsmooth.c, potentially executing arbitrary code on the device.
OpenCVE Enrichment