CVE-2026-28671

Summary

In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Software

VendorProductVersion RangeStatus
GoogleAndroid17affected
GoogleAndroid16-qpr2affected
GoogleAndroid16affected
GoogleAndroid15affected
GoogleAndroid14affected

Weaknesses

  • Information disclosure

References