VDB

ASB-A-369105011

ASB-A-369105011 PUBLISHED

In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an intent redirect. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Products

VendorProductVersions
platformpackages/providers/MediaProvider16-qpr2-next:0, 16-qpr2-next, 15:0

Timeline

  • Mar 1, 2026 CVE Published
  • May 15, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›