VYPR

MediaProvider

by Google

CVEs (6)

  • CVE-2026-0035HigMar 2, 2026
    risk 0.55cvss 8.4epss 0.00

    In createRequest of MediaProvider.java, there is a possible way for an app to gain read/write access to non-existing files due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2025-48578HigMar 2, 2026
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for…

  • CVE-2025-32327HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-48532HigSep 4, 2025
    risk 0.47cvss 7.3epss 0.00

    In markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for…

  • CVE-2023-35683MedSep 11, 2023
    risk 0.36cvss 5.5epss 0.00

    In bindSelection of DatabaseUtils.java, there is a possible way to access files from other applications due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0024MedMar 2, 2026
    risk 0.26cvss 4.0epss 0.00

    In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of media due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…