CVE-2024-43093 KEV
7.3
HIGH · CVSS 3.1 · EPSS 0.7% (pctl 52)
Patch first
On CISA KEV — known exploited in the wild, due 2024-11-28.
Description
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Scoring
| CVSS | 7.3 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 0.72% — more likely to be exploited than 52% of all CVEs |
| Weakness | CWE-176 |
| On CISA KEV | yes — remediate by 2024-11-28 |
| Public exploit | none known |
| Published | 2024-11-13 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Android Framework Privilege Escalation Vulnerability |
|---|---|
| Added | 2024-11-07 |
| Due | 2024-11-28 |
| Vendor / product | Android / Framework |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| android |
References
→ the Explorer · watch your stack · NVD