Impact
A race condition in MediaProvider.updateInternal can expose the contents of media files that are normally protected, allowing any local sensitive data. The flaw does not provide code execution or elevated privileges, and user interaction is not needed.
Affected Systems
Android devices running any version of the Android operating system are affected. The specific software versions in the 2026‑09‑01 security bulletin are not listed, but the issue applies to all builds that include the vulnerable MediaProvider.updateInternal implementation.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector is local; an attacker must run a local application or service that can read the media files. The CVSS score is 3.3 and the EPSS score is less than 1 %. The flaw is not listed in the CISA KEV catalog. Remote network access is not required, and no additional privileges beyond those normally granted to the app are needed.
OpenCVE Enrichment