
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0024 is a missing permission check vulnerability in Android's MediaProvider.java that allows local applications to reveal the file system location of media files without requiring any special privileges. The flaw exists in the isRedactionNeededForOpenViaContentResolver method and affects Android versions 14.0, 15.0, and 16.0 (including QPR2 variants). It was published on March 2, 2026, and carries a CVSS v3.1 base score of 4.0 (Medium) (Android Security Bulletin, Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization). Specifically, the isRedactionNeededForOpenViaContentResolver function in MediaProvider.java fails to enforce the necessary permission check before revealing the storage location of media files accessed via a content resolver. Because the attack vector is local and requires no privileges (PR:N) and no user interaction (UI:N), any app running on the device can query media file locations that should otherwise be redacted. No public technical write-up or proof-of-concept code has been identified at this time (Android Security Bulletin).
Successful exploitation results in local information disclosure — specifically, the physical storage path of media files on the device is exposed to unprivileged local applications. This could allow a malicious app to infer sensitive details about a user's media library organization, file naming conventions, or storage structure without the user's knowledge. There is no impact on integrity or availability, and the scope is limited to the local device with no evidence of lateral movement potential (Android Security Bulletin).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of reporting (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is detectable by Qualys scanners (detection IDs 610761 and 610767) (Android Security Bulletin).
Google released a patch as part of the Android Security Bulletin dated 2026-03-01, published on March 2, 2026. Users and administrators should apply the March 2026 security patch level (2026-03-01 or later) to all affected devices running Android 14, 15, or 16. Device manufacturers such as Samsung have begun distributing this patch through their own update channels. No configuration-based workaround is available; patching is the only remediation (Android Security Bulletin, SammyFans).
The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in the March 2026 Android OS update, including CVE-2026-0024, warning of potential remote code execution risks from the broader patch set (CIS Advisory). Community discussion has been minimal, consistent with the vulnerability's medium severity and lack of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."