CVE CVE

CVE-2024-43093

CISA Known Exploited Vulnerability (KEV)

Android Framework Privilege Escalation Vulnerability

November 7, 2024

November 28, 2024

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
7.8
Severity:

HIGH

Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2

Not defined