CVE-2024-34721 Information

Description

In ensureFileColumns of MediaProvider.java there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Reference

https://android.googlesource.com/platform/packages/providers/MediaProvider/+/7a1cbf5a8e17e6bff7c835fdd30dcc42b681db0a https://source.android.com/security/bulletin/2024-07-01

Share on: