In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-08 19:17
Updated : 2026-09-10 17:17
NVD link : CVE-2026-28671
Mitre link : CVE-2026-28671
CVE.ORG link : CVE-2026-28671
JSON object : View
Products Affected
No product.
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
