First published: Mon Jul 01 2024(Updated: )
In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =12.0 | |
Android | =12.1 | |
Android | =13.0 | |
Android | =14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34721 is classified as a local information disclosure vulnerability.
To fix CVE-2024-34721, update to the latest version of Android that addresses this vulnerability.
CVE-2024-34721 affects Android versions 12.0, 12.1, 13.0, and 14.0.
CVE-2024-34721 is caused by improper input validation in the ensureFileColumns function of MediaProvider.java.
Yes, CVE-2024-34721 can be exploited without any user interaction.