Executive brief
A privilege escalation vulnerability exists in the Android Framework's ExternalStorageProvider.java due to incorrect Unicode normalization in the shouldHideDocument function. This flaw allows a local attacker to bypass file path filters designed to protect sensitive directories, potentially leading to elevated privileges.
Affected products
- Google Android 12, 12.1, 13, 14, 15
Timeline
- 2024-11-07: disclosed
- 2024-11-07: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
- 2024-11-13: exploited: Reported as exploited in the wild.
- 2025-03-01: advisory: Vendor advisory published.