CVE-2021-0337
NixOS vulnerability analysis and mitigation

Overview

In moveInMediaStore of FileSystemProvider.java, there is a file exposure vulnerability due to stale metadata affecting Android versions 8.1, 9, 10, and 11. The vulnerability was assigned CVE-2021-0337 and requires user execution privileges for exploitation, though user interaction is not needed for exploitation (CVE List).

Technical details

The vulnerability exists in the FileSystemProvider.java component, specifically in the moveInMediaStore function. It involves a potential file exposure issue that occurs due to stale metadata handling. The vulnerability affects multiple versions of the Android operating system, including Android 8.1, Android 9, Android 10, and Android 11. The issue has been tracked under Android ID: A-157474195 (CVE List).

Impact

The vulnerability could lead to local escalation of privilege when successfully exploited. The attack requires user execution privileges to be effective, though it doesn't require direct user interaction for exploitation (CVE List).

Exploitability

The vulnerability requires user execution privileges for successful exploitation. However, it's notable that user interaction is not needed for exploitation, making it potentially more dangerous in scenarios where an attacker has already gained initial access to the device (CVE List).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management