VDB
GHSA-q253-vq9r-f672
GHSA-q253-vq9r-f672
PUBLISHED
CVSS 10 CRITICAL
In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Risk Scores
CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Timeline
- Mar 10, 2026 CVE Published
- Apr 10, 2026 Security Advisory