ASB-A-200813547
Dashboard / Vulnerabilities / ASB-A-200813547
Summary:
Details: In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private directories protection due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
References: https://source.android.com/security/bulletin/2022-03-01, https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/0dc5048914eb6a7f919c8749172b971cbb315870, https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/9ff84f6d353a7647efba91d74e31d17ba6b765b7
Affected packages
Package
Name: platform/packages/providers/DownloadProvider
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
