Two high-severity vulnerabilities were disclosed in MolotovCherry Android-ImageMagick7, affecting releases prior to 7.1.2-10 and 7.1.2-11. CVE-2026-33854 is an out-of-bounds write flaw classified as CWE-787, which can lead to memory corruption and carries a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. CVE-2026-4755 is an improper input validation issue classified as CWE-20, affecting versions before 7.1.2-11 with a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
The disclosures indicate both flaws could have severe impact on confidentiality, integrity, and availability, with the input validation bug standing out because it is network-exploitable and requires no privileges or user interaction. References added to the CVE records point to GitHub pull requests, including PR #193, suggesting fixes or remediation work is available upstream. Organizations using Android-ImageMagick7 should identify exposed deployments and prioritize upgrades to patched versions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-24, a new CVE entry documented an improper input validation vulnerability (CWE-20) in MolotovCherry Android-ImageMagick7 affecting versions before 7.1.2-11. The record included a high-severity CVSS v3.1 vector and referenced GitHub pull request #193.
On 2026-03-24, a new CVE entry documented an out-of-bounds write vulnerability (CWE-787) in MolotovCherry Android-ImageMagick7 affecting versions before 7.1.2-10. The record included a high-severity CVSS v3.1 score and a GitHub pull request reference.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.