Microsoft disclosed "Dirty Stream", a path traversal-related vulnerability pattern in Android apps that accept shared files from other apps and trust filenames supplied by remote content providers. The flaw can let a malicious app overwrite files inside a target app’s private directory, creating paths to arbitrary code execution, theft of authentication tokens, and exposure of other sensitive data. Microsoft said the issue affected multiple popular Google Play apps with a combined install base exceeding 4 billion.
Microsoft highlighted vulnerable apps including Xiaomi File Manager and WPS Office, and demonstrated code execution in Xiaomi File Manager. The company said exploitation could also expose stored SMB and FTP credentials and enable access to local network shares beyond the device itself. Microsoft coordinated fixes with affected developers by February 2024 and worked with Google on developer guidance for safer Android file-sharing implementations, reinforcing the need for apps handling shared content to validate filenames and file paths before writing data.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft publicly disclosed the 'dirty stream' attack as a common Android app vulnerability pattern that could lead to arbitrary code execution and theft of authentication tokens and other sensitive data. The company said the affected Google Play apps it identified represented more than four billion installs.
Microsoft said fixes had been deployed for the identified vulnerable apps by February 2024. Xiaomi addressed the issue in File Manager version V1-210593, and WPS Office addressed it as of version 17.0.0.
Microsoft collaborated with Google to publish guidance on the Android Developers website to help developers avoid trusting filenames supplied by remote content providers. The guidance recommended using generated filenames, sanitizing paths, and ensuring cached files stay within dedicated directories.
Microsoft achieved arbitrary code execution in WPS Office version 16.8.1 using the same vulnerability pattern involving untrusted filenames from remote content providers.
Microsoft achieved arbitrary code execution against Xiaomi File Manager version V1-210567 by exploiting the vulnerable file-handling pattern. It also found the app exposed stored SMB and FTP credentials, enabling potential access to local network shares through the compromised device.
Microsoft identified a path traversal-related vulnerability pattern in Android apps that process shared files from other apps, allowing malicious apps to overwrite files in a target app's private directory. Microsoft found the issue affected multiple popular Google Play apps, including Xiaomi File Manager and WPS Office.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
developer.android.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.