The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/.
| Software | From | Fixed in |
|---|---|---|
| google / android | 1.6 | 1.6.x |
| google / android | 2.1 | 2.1.x |
| google / android | 2.3-rev1 | 2.3-rev1.x |
| google / android | 1.5 | 1.5.x |
| google / android | 2.2.1 | 2.2.1.x |
| google / android | 2.2.2 | 2.2.2.x |
| google / android | 2.2 | 2.2.x |
| google / android | 2.2-rev1 | 2.2-rev1.x |
| google / android | - | 2.3.3.x |