Impact
In the MediaProvider component of Android, a logic flaw in getQueryBuilderInternal allows an unprivileged application to query location metadata that should be protected. This permissions bypass leads to local disclosure of sensitive location data. The flaw requires no additional privileges, no user interaction, and no network communication, so the information can be collected silently by a malicious or compromised app. The weakness is rooted in insufficient access control (CWE-862).
Affected Systems
The implementation, specifically the getQueryBuilderInternal path. Any device running a version of Android that has not yet applied the relevant fix is potentially at risk. Specific release information is not provided, so regular security updates are the primary indicator of coverage. The vendor responsible is Google.
Risk and Exploitability
Exploitation can and the low CVSS score (3.3) reflects the privacy impact rather than a system compromise. The EPSS score of less than 1% indicates that attackers rarely target this flaw, and there is no record of widespread exploitation in CISA's KEV catalogue. Nonetheless, because the attack does not require user cooperation or elevated privileges, a malicious application can quietly harvest location data once installed. The attack vector is likely a malicious or compromised app that calls MediaProvider queries as part of normal functionality.
OpenCVE Enrichment