PT-2024-30289 · Unknown · Mediaprovider
Omar Eissa
·
Published
2024-11-01
·
Updated
2024-12-17
·
CVE-2024-43089
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MediaProvider (affected versions not specified)
Description
The issue is related to a missing permission check in the
updateInternal method of MediaProvider.java. This could allow access to another app's files, leading to local escalation of privilege without needing additional execution privileges. User interaction is not required for exploitation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Default Permissions
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mediaprovider