Popular Android Apps Like Xiaomi, WPS Office Vulnerable to File Overwrite Flaw
ID: 818f0d07-1980-5e35-9ac6-ae9b5e87eebe
STIX ID: report--818f0d07-1980-5e35-9ac6-ae9b5e87eebe
Feed Name: The Hacker News
Threat Score
Microsoft disclosed a content-provider path traversal vulnerability dubbed "Dirty Stream" affecting popular Android apps (notably Xiaomi File Manager and WPS Office) that allows a malicious app to overwrite files in another app's internal storage via crafted intents, potentially enabling token theft or arbitrary code execution; vendors have patched the issue as of February 2024 and Google published developer guidance on sanitizing filenames.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
