logo

Microsoft warns of "Dirty Stream" attack impacting Android apps

ID: aed1243e-6e7c-5d76-a5a1-94b9f6226fdc

STIX ID: report--aed1243e-6e7c-5d76-a5a1-94b9f6226fdc

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-05-02

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Microsoft disclosed a vulnerability dubbed 'Dirty Stream' in which malicious Android apps can abuse improperly implemented content providers and custom intents to send manipulated filenames or paths that cause target apps to write or execute files in sensitive directories, risking arbitrary code execution and data/secret theft. The researchers identified the pattern in apps representing over four billion installations (notably Xiaomi File Manager and WPS Office), worked with vendors to deploy fixes, and prompted Android/Google to update developer guidance; users are advised to keep apps updated and avoid untrusted APK sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.