logo

“Dirty stream” attack: Discovering and mitigating a common vulnerability pattern in Android apps

ID: 93e52393-d52d-52d1-845f-55655f02a84d

STIX ID: report--93e52393-d52d-52d1-845f-55655f02a84d

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2024-05-01

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence describes a widespread Android path-traversal vulnerability pattern in content providers/FileProvider where a malicious app can supply crafted content URIs and filenames to cause share-target apps to write files into their internal storage, enabling arbitrary code execution and credential theft; the blog includes a Xiaomi File Manager case study (native library replacement and SMB/FTP credential exfiltration), notes affected high-installation apps (over 4 billion installs across identified apps), documents coordinated disclosure and fixes, and provides developer/user remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.