CVE-2024-43093

HIGH KEV

Android - Local Privilege Escalation via Unicode Normalization Bypass in ExternalStorageProvider

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-43093 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 7, 2024.

Description

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Scores

CVSS v3 7.3
EPSS 0.0014
EPSS Percentile 33.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2024-11-07
VulnCheck KEV 2024-11-04
InTheWild.io 2024-11-04
ENISA EUVD EUVD-2024-40034
CWE
CWE-176
Status published
Products (5)
google/android 12.0
google/android 12.1
google/android 13.0
google/android 14.0
google/android 15.0
Published Nov 13, 2024
KEV Added Nov 07, 2024
Tracked Since Feb 18, 2026