logo

Popular Android Apps Like Xiaomi, WPS Office Vulnerable to File Overwrite Flaw

ID: 818f0d07-1980-5e35-9ac6-ae9b5e87eebe

STIX ID: report--818f0d07-1980-5e35-9ac6-ae9b5e87eebe

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-05-02

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Microsoft disclosed a content-provider path traversal vulnerability dubbed "Dirty Stream" affecting popular Android apps (notably Xiaomi File Manager and WPS Office) that allows a malicious app to overwrite files in another app's internal storage via crafted intents, potentially enabling token theft or arbitrary code execution; vendors have patched the issue as of February 2024 and Google published developer guidance on sanitizing filenames.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.