Android DocumentsUI Local Privilege Escalation Vulnerability
Vulnerability
A vulnerability in the Android DocumentsUI application allows for local privilege escalation. This issue arises from improper input validation in the 'getCallingAppName' function of the 'Shared.java' file. The flaw can be exploited to mislead users into granting file access through deceptive wording in a permission popup. Notably, this vulnerability does not require any additional execution privileges and can be exploited without user interaction.
Impact
Exploitation of this vulnerability could lead to unauthorized access to files or data, allowing a user to gain elevated privileges and potentially modify or delete sensitive information.
Remediation
Users can update their devices to the September 2025 security patch level to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
