The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.642
EPSS Ranking 98.4%