Platform Packages Providers Downloadprovider vulnerabilities
4 known vulnerabilities affecting platform/packages_providers_downloadprovider.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN4
Vulnerabilities
Page 1 of 1
CVE-2025-26427UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 13:0, < 13:2025-05-01+1 more2025-05-01
CVE-2025-26427 CVE-2025-26427: In multiple locations, there is a possible Android/data access due to a path traversal error
In multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-26417UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 12:0, < 12:2025-03-01+4 more2025-03-01
CVE-2025-26417 CVE-2025-26417: In checkWhetherCallingAppHasAccess of DownloadProvider
In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0032UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 12:0, < 12:2025-03-01+3 more2025-03-01
CVE-2024-0032 CVE-2024-0032: In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation
In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39697UNKNOWN≥ 11:0, < 11:2022-03-01≥ 12:0, < 12:2022-03-01+1 more2022-03-01
CVE-2021-39697 CVE-2021-39697: In checkFileUriDestination of DownloadProvider
In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private directories protection due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv