Description
In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Local Information Disclosure
Action: Apply Patch
AI Analysis

Impact

A race condition in MediaProvider.updateInternal can expose the contents of media files that are normally protected, allowing any local sensitive data. The flaw does not provide code execution or elevated privileges, and user interaction is not needed.

Affected Systems

Android devices running any version of the Android operating system are affected. The specific software versions in the 2026‑09‑01 security bulletin are not listed, but the issue applies to all builds that include the vulnerable MediaProvider.updateInternal implementation.

Risk and Exploitability

Based on the description, it is inferred that the likely attack vector is local; an attacker must run a local application or service that can read the media files. The CVSS score is 3.3 and the EPSS score is less than 1 %. The flaw is not listed in the CISA KEV catalog. Remote network access is not required, and no additional privileges beyond those normally granted to the app are needed.

Generated by OpenCVE AI on September 11, 2026 at 05:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Android 2026‑09‑01 security patch that contains the fix for MediaProvider.updateInternal.
  • Reduce the permissions of applications that use the MediaProvider API by revoking unnecessary READ_MEDIA_* or READ_EXTERNAL_STORAGE permissions, ensuring they only have access to the media files they truly need.
  • If the patch cannot be applied immediately, disable or uninstall third‑party applications that grant broad media read access until the device is updated and permissions are tightened.

Generated by OpenCVE AI on September 11, 2026 at 05:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Fri, 11 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Race Condition in MediaProvider.updateInternal Allows Local Information Disclosure

Fri, 11 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Race Condition in MediaProvider.updateInternal Allows Local Information Disclosure
Weaknesses CWE-200

Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Race Condition in MediaProvider Allows Local Information Disclosure

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-367
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Race Condition in MediaProvider Allows Local Information Disclosure
Weaknesses CWE-200

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T16:13:49.570Z

Reserved: 2026-03-02T19:11:24.242Z

Link: CVE-2026-28671

cve-icon Vulnrichment

Updated: 2026-09-10T16:13:40.087Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:57.087

Modified: 2026-09-23T19:35:43.603

Link: CVE-2026-28671

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:30:02Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition