Description


In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Related CPE's


o

google

android

4

Weaknesses



NVD-CWE-noinfo

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-922

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5.5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2024-07-09T19:15:14.277Z

1 year ago

Last modified

2024-12-17T17:17:31.613Z

1 year ago