CVE-2026-0024

EUVD-2026-9238
In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of media due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
googleandroid
14.0
googleandroid
15.0
googleandroid
16.0
googleandroid
16.0:qpr2_beta_1
googleandroid
16.0:qpr2_beta_2
googleandroid
16.0:qpr2_beta_3
𝑥
= Vulnerable software versions