CVE-2026-0035 - Apache MediaProvider Local Privilege Escalation
CVE ID : CVE-2026-0035
Published : March 2, 2026, 7:16 p.m. | 2 hours, 28 minutes ago
Description : In createRequest of MediaProvider.java, there is a possible way for an app to gain read/write access to non-existing files due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 2, 2026, 7:16 p.m. | 2 hours, 28 minutes ago
Description : In createRequest of MediaProvider.java, there is a possible way for an app to gain read/write access to non-existing files due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...