HIGH🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2024-43093

CVSS 7.3v3.1pub. 2024-11-13upd. 2025-10-23

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
  • Google Android

    OS
    Google
    12.012.113.014.015.0

CISA KEV — detailsi

Vendori
Android
Producti
Framework
Added to KEVi
November 7, 2024
Remediation deadline (US Federal)i
November 28, 2024(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Android Framework contains an unspecified vulnerability that allows for privilege escalation.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 28 listopada 2024
CWE
References

Related vulnerabilities

CVE-2020-16010CRITICAL9.6⚠ KEVPL ✓same product

Heap buffer overflow w Google Chrome na Android — sandbox escape

CVE-2016-1019CRITICAL9.8⚠ KEVPL ✓same product

Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku

CVE-2026-78937CRITICAL9.6same product

Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever...

CVE-2026-79129CRITICAL9.6same product

Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lev...

CVE-2026-79152CRITICAL9.8same product

Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local at...