Impact
Verizon Cloud for Android (com.vcast.mediamanager) before version 26.7.10 has a path traversal flaw that lets a co‑resident malicious application supply a crafted _display_name value containing path‑traversal sequences. The flaw exists in the exported activities OneTouchUploadActivity and PrintShopCloudActivity and is triggered via ACTION_SEND or ACTION_SEND_MULTIPLE intents. Because the filename is concatenated without sanitization, an attacker can write arbitrary bytes to locations outside the intended staging directory and inject attacker‑controlled content directly into the authenticated user’s Verizon Cloud account, all without user interaction.
Affected Systems
Verizon Cloud for Android, version 26.7.10 and earlier. The affected application package is com.vcast.mediamanager. Users running any pre‑26.7.10 build are vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity vulnerability, while the EPSS value of less than 1% suggests a low probability of exploitation at the current time. The flaw is not listed in the CISA KEV catalog. Exploitation requires a malicious co‑resident app to target the exported upload activities; no user‑initiated interaction is needed beyond installing the attacker’s application or sending a crafted intent. This local attack surface limits the attack to devices where the attacker can install an app, but once present, it allows arbitrary file write that bypasses permission controls.
OpenCVE Enrichment