CVE-2010-4804 is an information disclosure vulnerability in the Android browser prior to version 2.3.4. The vulnerability exists in the handling of crafted content:// URIs by the browser, specifically in the BrowserActivity.java and BrowserSettings.java components of com/android/browser/. Remote attackers can exploit this flaw to access and obtain contents from the SD card of the device by tricking the browser into processing malicious content:// URIs.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary module: 'android_htmlfileprovider.rb'. The module exploits a cross-domain vulnerability (CVE-2010-4804) in the Android web browser, allowing an attacker to exfiltrate files from a vulnerable device. The exploit works by serving malicious HTML/JavaScript to the victim, which uses the vulnerable content provider to read files from the device and POST them back to the attacker's server. The default targeted files are '/proc/version', '/proc/self/status', and '/data/system/packages.list', but this can be configured. The module is operational and can be used to demonstrate or leverage the vulnerability for file disclosure on affected Android devices. The attack vector is browser-based, requiring the victim to visit a malicious web page. The only file in the repository is a Ruby script for Metasploit, which dynamically generates the payload and handles exfiltrated data.
This repository contains two PHP proof-of-concept exploits (poc.php and poc2.php) for CVE-2010-4804, an Android information disclosure vulnerability affecting versions prior to 2.3.4 and up to 3.2. The exploits are designed to be hosted on a web server and visited by a vulnerable Android device using the default browser. Both scripts orchestrate a multi-stage attack: 1. The user is enticed to click a malicious link, which initiates a series of redirects and downloads a crafted HTML/JavaScript payload to the device. 2. The payload, when executed in the context of the local device (via content:// or file:// URIs), uses JavaScript and AJAX to read arbitrary files from the device's filesystem (e.g., /proc/version, /sdcard/img.jpg). 3. The stolen file contents are then base64-encoded and POSTed back to the attacker's server, where they are saved to files.txt. The two PoCs demonstrate different techniques for exploiting the vulnerability: poc.php uses the content:// URI scheme, while poc2.php demonstrates a cross-protocol attack using iframes and file:// URIs. Both scripts are well-commented and modular, with clear instructions for use. The repository is a classic example of a browser-based attack vector targeting Android devices, and does not include any detection scripts or fake code.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.