Impact
A memory safety flaw exists in the stpropnci_process_std function of stpropnci_std.cc due to a missing bounds check. The vulnerability can be exploited to gain local privilege escalation on an affected device without the need for any additional execution privileges. The description states that no user interaction is required for exploitation.
Affected Systems
The affected vendor is Google and the product is Android. The flaw resides in the stpropnci_process_std component, and there is no explicit version information provided in the CVE data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and the lack of an EPSS score means the current exploit probability is unknown. The vulnerability is listed as not part of the CISA KEV catalog. Because user interaction is not required and the flaw allows local privilege escalation, a local attacker—such as a user with access to the device—could exploit the issue. The known lack of more advanced privileges means the impact is limited to local privilege elevation rather than remote code execution.
OpenCVE Enrichment