CVE-2017-0388: Infoleak
An elevation of privilege vulnerability in the External Storage Provider could enable a local secondary user to read data from an external storage SD card inserted by the primary user. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32523490.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0388?
CVE-2017-0388 is rated as High due to its potential to allow local secondary users to bypass operating system protections and access data from an external SD card.
How do I fix CVE-2017-0388?
To mitigate CVE-2017-0388, ensure that your Android devices are updated to versions that include the security patch provided by Google.
Which versions of Android are affected by CVE-2017-0388?
CVE-2017-0388 affects Android versions 6.0, 6.0.1, 7.0, and 7.1.0.
What kind of vulnerability is CVE-2017-0388?
CVE-2017-0388 is classified as an elevation of privilege vulnerability in the External Storage Provider.
Who is the vendor associated with CVE-2017-0388?
The vendor associated with CVE-2017-0388 is Google, as it pertains to the Android operating system.