logo

Billions of Android Devices Open to 'Dirty Stream' Attack

ID: 3070871d-ce88-5611-b08e-ec3e3df914de

STIX ID: report--3070871d-ce88-5611-b08e-ec3e3df914de

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-05-02

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Microsoft researchers disclosed a common Android content-provider vulnerability that lets a malicious app send crafted filenames to consuming apps, which may blindly use those filenames to create or overwrite files in their private data space—potentially leading to authentication token theft, configuration manipulation, or remote/native code execution. The issue affects many apps (including some with hundreds of millions to over a billion installs); Microsoft coordinated disclosure with Google and vendors, and Google published developer guidance while some vendors have issued fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.