CVE-2024-43093: Android Framework Privilege Escalation Vulnerability
Android Framework contains an unspecified vulnerability that allows for privilege escalation.
Other sources
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
— MITRE
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-43093?
CVE-2024-43093 has been classified as a high-severity vulnerability.
How do I fix CVE-2024-43093?
To fix CVE-2024-43093, users should update to the latest version of the Android framework that includes the security patch.
Which versions of Android are affected by CVE-2024-43093?
CVE-2024-43093 affects Android versions 12.0 through 15.0.
What type of vulnerability is CVE-2024-43093?
CVE-2024-43093 is a privilege escalation vulnerability in the Android Framework.
Is CVE-2024-43093 being actively exploited?
There have been reports indicating that CVE-2024-43093 has been used in targeted attacks.