Vulnerability Intelligence Report
Android Framework Privilege Escalation Vulnerability
CVE-2024-43093
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
7.3
HIGH
Exploitability:1.4
Impact Score:5.9
EPSS Probability:0.71%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-176 ↗CWE-176 Improper Handling of Unicode Encoding
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Android | 15 (affected), 14 (affected), 13 (affected), 12L (affected), 12 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Android (associated with Google Inc. or Open Handset Alliance) · Vendor · USA |
| Reserved | 2024-08-05T14:29:53 |
| Published | 2024-11-13T17:25:14 |
| Last Updated | 2025-10-21T22:55:36 |
Community Chatter & Buzz