Impact
Ekia File Manager 1.2.7 exposes an Android ContentProvider that is exported without any caller permission checks. The provider maps the URI path supplied by the Java File constructor directly to a filesystem path. Because no readPermission, writePermission, or android:permission attribute is declared, any application on the same device can invoke the provider’s query, openFile, or delete methods and read, create, overwrite, or delete files that the File Manager process can access. This flaw allows an attacker to compromise confidentiality, integrity, and availability of local files, potentially leaking sensitive data or corrupting user files.
Affected Systems
The vulnerable product is Ekia File Manager, version 1.2.7, running on Android devices. All installations of this version are impacted, regardless of the device model or Android release, as the flaw is built into the ContentProvider.
Risk and Exploitability
The risk is high due to the local nature of the attack vector and the lack of permission checks on the exported provider. With a CVSS score of 8.5, an attacker can read, create, overwrite, or delete any file the File Manager’s process can access, compromising confidentiality, integrity, and availability of local data. The EPSS score of < 1% indicates a low but non‑zero probability of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. The local attack surface, however, means that an adversary with a malicious Android application on the device could exploit the flaw without external network access.
OpenCVE Enrichment