Description
In getQueryBuilderInternal of MediaProvider.java, there is a possible way to retrieve location metadata due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Local Information Disclosure
Action: Assess Impact
AI Analysis

Impact

In the MediaProvider component of Android, a logic flaw in getQueryBuilderInternal allows an unprivileged application to query location metadata that should be protected. This permissions bypass leads to local disclosure of sensitive location data. The flaw requires no additional privileges, no user interaction, and no network communication, so the information can be collected silently by a malicious or compromised app. The weakness is rooted in insufficient access control (CWE-862).

Affected Systems

The implementation, specifically the getQueryBuilderInternal path. Any device running a version of Android that has not yet applied the relevant fix is potentially at risk. Specific release information is not provided, so regular security updates are the primary indicator of coverage. The vendor responsible is Google.

Risk and Exploitability

Exploitation can and the low CVSS score (3.3) reflects the privacy impact rather than a system compromise. The EPSS score of less than 1% indicates that attackers rarely target this flaw, and there is no record of widespread exploitation in CISA's KEV catalogue. Nonetheless, because the attack does not require user cooperation or elevated privileges, a malicious application can quietly harvest location data once installed. The attack vector is likely a malicious or compromised app that calls MediaProvider queries as part of normal functionality.

Generated by OpenCVE AI on September 11, 2026 at 05:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android firmware update that contains the MediaProvider patch.
  • Revoke location permissions from applications that do not require them, limiting their ability to query location metadata.
  • Use the Android app sandboxing and permission model to ensure only trusted applications can invoke MediaProvider queries.

Generated by OpenCVE AI on September 11, 2026 at 05:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Fri, 11 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Local Information Disclosure in Android MediaProvider Due to Permissions Bypass

Fri, 11 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Local Information Disclosure in Android MediaProvider Due to Permissions Bypass

Thu, 10 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title MediaProvider Location Metadata Bypass Leading to Local Information Disclosure
Weaknesses CWE-200
CWE-285

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title MediaProvider Location Metadata Bypass Leading to Local Information Disclosure
Weaknesses CWE-200
CWE-285

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In getQueryBuilderInternal of MediaProvider.java, there is a possible way to retrieve location metadata due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T17:08:37.565Z

Reserved: 2026-03-02T19:11:11.727Z

Link: CVE-2026-28622

cve-icon Vulnrichment

Updated: 2026-09-10T17:08:31.332Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:54.200

Modified: 2026-09-15T14:07:35.353

Link: CVE-2026-28622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T23:30:04Z

Weaknesses