Impact
The vulnerability emerges from the ExpoShareIntentModule.kt file copy routine of the achorein expo-share-intent library, where inadequate handling of the _display_name argument permits an attacker to traverse directories and read files beyond the intended scope. This path traversal flaw exposes sensitive data stored on the device and can lead to confidentiality breaches. The impact is local, requiring an attacker to have control over input provided to the getDataColumn function.
Affected Systems
The flaw affects the achorein expo-share-intent library, specifically versions up to and including 8.0.0. Any project using these versions without upgrading to 8.0.1 or later remains vulnerable. No other vendors or product variants are listed.
Risk and Exploitability
The publicly published CVSS score of 4.8 indicates moderate severity, and no EPSS score is available, suggesting limited or undocumented exploitation activity. The attack requires a local approach—an attacker must interact with the target device or application to supply malicious input. Although the flaw is not listed in the CISA KEV catalog, it still presents a real risk to installations that have not applied the forthcoming patch.
OpenCVE Enrichment