CVE-2024-43093

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive...

Basic Information

CVE State
PUBLISHED
Reserved Date
August 05, 2024
Published Date
November 13, 2024
Last Updated
November 13, 2024
Vendor
Google
Product
Android
Description
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS Scores

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2024-11-07 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2024-11-07 00:00:00 UTC