PT-2024-7664 · Google · Android

Published

2024-11-01

·

Updated

2026-01-11

·

CVE-2024-43093

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description A privilege escalation vulnerability exists in the Android Framework component, specifically within the ExternalStorageProvider.java file. This flaw is due to an incorrect Unicode normalization when handling file paths, potentially bypassing file path filters designed to restrict access to sensitive directories. Successful exploitation of this issue could allow an attacker to gain elevated privileges with no additional execution privileges needed, potentially granting unauthorized access to directories such as Android/data, Android/obb, and Android/sandbox. User interaction is required for exploitation. Reports indicate that this vulnerability, tracked as CVE-2024-43093, is actively being exploited in the wild, with limited, targeted attacks observed.
Recommendations Update your Android device to the latest available version to address this vulnerability.

Exploit

Fix

LPE

RCE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ASB-A-341680936
BDU:2024-09108
CVE-2024-43093

Affected Products

Android