CVE-2024-43093

Confirmed PUBLISHED

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive...

Google · Android
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.3 High

At a Glance

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

java android cisa
CVE Published
Nov 13, 2024
Exploitation Reported
Nov 07, 2024
CVSS
7.3 High
EPSS
Low complexity

Affected Versions

Vendor Product Version Status
Google
Android

15

Affected
Google
Android

14

Affected
Google
Android

13

Affected
Google
Android

12L

Affected
Google
Android

12

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.