CVE-2024-43089
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Nov 13, 2024
Updated: Nov 15, 2024
CWE ID 276
Summary
CVE-2024-43089 is a vulnerability affecting the MediaProvider.java component in certain applications. The issue lies in the updateInternal function, where a missing permission check could allow unauthorized access to files belonging to other apps. This vulnerability grants local escalation of privilege, meaning an attacker can exploit it without requiring any additional execution privileges or user interaction.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Android