Impact
A buffer overflow in the forEachLine function of MountRegistry.cpp allows an out‑of‑bounds read, which can be leveraged to obtain higher privileges on the same device. The flaw does not require additional execution privileges and does not need user interaction, meaning any local user can potentially exploit the issue. The weakness is a classic CWE‑120 out‑of‑bounds read vulnerability.
Affected Systems
The vulnerability is present in Google Android systems where the MountRegistry component is compiled. No specific version numbers are listed, so all Android releases that include the current implementation of MountRegistry.cpp may be affected until a patch is released.
Risk and Exploitability
The CVSS score of 7.8 indicates high impact, and although the EPSS score is not available, the lack of user interaction makes the flaw attractive to local attackers. The vulnerability is not currently listed in the CISA KEV catalog. An attacker with local device access can trigger the out‑of‑bounds read to elevate privileges, potentially gaining root or administrator access depending on the device’s configuration.
OpenCVE Enrichment