CVE-2012-4220 is a vulnerability in diagchar_core.c of the Qualcomm Innovation Center (QuIC) Diagnostics (DIAG) kernel-mode driver for Android versions 2.3 through 4.2. The vulnerability allows local attackers to execute arbitrary code or cause a denial of service by passing crafted arguments to the diagchar_ioctl call. The issue is due to improper handling of user-supplied arguments, leading to an incorrect pointer dereference in kernel space.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a local privilege escalation exploit for CVE-2012-4220, targeting the ZTE Open (roamer2) and several other Android devices with specific build versions. The exploit leverages a vulnerability in the diag kernel driver (/dev/diag) to inject code and patch the sys_setresuid kernel function, allowing the process to gain root privileges. The main payload is a precompiled setuid-root 'su' binary embedded in su.h, which is written to /system/xbin/su after successful exploitation, enabling persistent root access. The exploit is implemented in C, with the main logic in main.c and supporting code in libdiagexploit/diag.c and diag.h. The exploit requires local access to the device, the ability to access /dev/diag, and the ability to remount the /system partition as read-write. The repository is structured for building with the Android NDK, and is not part of a larger exploit framework.
This repository contains an Android application and native code that implements a local privilege escalation exploit targeting specific Android devices (Fujitsu F-03D, Samsung SC-05D, Sony SO-05D, Sharp IS17SH) with certain build IDs. The exploit leverages a vulnerability in the diag kernel driver and the uevent_helper kernel parameter to gain root privileges. The Java component (MainActivity.java) uses a content provider to obtain a file descriptor to /dev/diag, which is then passed to native code via JNI. The native code (main.c, jni.c, common.c) performs the core exploit logic: it injects a helper command path into kernel memory, manipulates the uevent_helper parameter, and ultimately copies /system/bin/sh to /dev/sh, setting it as a setuid-root shell. The exploit is operational and, if successful, provides a persistent root shell at /dev/sh. The repository structure includes Android build files, JNI C source code, and the main Java activity. The exploit is not part of a framework and is specifically tailored for the listed device models and build IDs.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.