
Cloud Vulnerability DB
A community-led vulnerabilities database
In moveInMediaStore of FileSystemProvider.java, there is a file exposure vulnerability due to stale metadata affecting Android versions 8.1, 9, 10, and 11. The vulnerability was assigned CVE-2021-0337 and requires user execution privileges for exploitation, though user interaction is not needed for exploitation (CVE List).
The vulnerability exists in the FileSystemProvider.java component, specifically in the moveInMediaStore function. It involves a potential file exposure issue that occurs due to stale metadata handling. The vulnerability affects multiple versions of the Android operating system, including Android 8.1, Android 9, Android 10, and Android 11. The issue has been tracked under Android ID: A-157474195 (CVE List).
The vulnerability could lead to local escalation of privilege when successfully exploited. The attack requires user execution privileges to be effective, though it doesn't require direct user interaction for exploitation (CVE List).
The vulnerability requires user execution privileges for successful exploitation. However, it's notable that user interaction is not needed for exploitation, making it potentially more dangerous in scenarios where an attacker has already gained initial access to the device (CVE List).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."