High severity7.3CISA KEVNVD Advisory· Published Nov 13, 2024· Updated Jun 17, 2026
CVE-2024-43093
CVE-2024-43093
Description
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
- (no CPE)range: 15
Patches
Vulnerability mechanics
References
3- android.googlesource.com/platform/frameworks/base/+/7f83c671626f9bf993581f4598c22482d87cba10nvdPatch
- source.android.com/security/bulletin/2025-03-01nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdThird Party AdvisoryUS Government Resource
News mentions
1- Critical Remote Code Execution Vulnerability Patched in AndroidSecurityWeek · May 5, 2026