Junglewise Threat Intelligence

CVE-2026-89038: Verizon Cloud for Android path traversal in file sharing

CVE-2026-89038 · Severity: medium · CVSS 6.2 · Published 2026-09-17

Executive brief

Verizon Cloud for Android is a mobile app used to store and sync photos and files to a cloud account. A flaw in how the app handles files shared from other apps allows malicious apps installed on the same device to inject arbitrary files into a user's Verizon Cloud account without any user interaction or additional permissions. An attacker could inject malware, inappropriate content, or forged documents into the victim's cloud storage.

Technical details

This is a path traversal vulnerability (CWE-22) in the file-sharing intent handlers of Verizon Cloud for Android. Two exported activities—OneTouchUploadActivity and PrintShopCloudActivity—accept files via ACTION_SEND and ACTION_SEND_MULTIPLE intents without validating the filename metadata (_display_name). The vulnerable code concatenates the attacker-supplied filename directly into a staging directory path without basename stripping or containment checks, allowing sequences like "../" to write files outside the intended staging folder. The staged file is then automatically uploaded to the user's cloud account. Exploitation requires only that Verizon Cloud be signed in and the device be on Wi-Fi (to skip confirmation dialogs); the attacker app requires zero permissions. The vulnerability was fixed in version 26.7.10 by sanitizing filenames via basename extraction and canonical-path validation.

Affected products

  • Verizon Cloud for Android before 26.7.10

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: fix available in version 26.7.10

References