A vulnerability in Android's implementation of java.io.ObjectInputStream (prior to version 5.0.0) fails to properly verify that deserialized objects meet the requirements for serialization. This flaw allows an attacker to craft a serialized object with a malicious finalize method (such as in android.os.BinderProxy) and deliver it via an ArrayMap Parcel in an intent to system_service. Upon deserialization, the attacker's code in the finalize method can be executed, leading to arbitrary code execution within the context of the system service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) local privilege escalation exploit targeting CVE-2014-7911 on Nexus 5 devices running Android 4.4.4 (KTU8P). The exploit is implemented as an Android application, with the main logic in 'cve20147911/src/c/v/e/MainActivity.java'. The exploit crafts a malicious BinderProxy object and uses a ROP chain to escalate privileges from a regular app to the system user, demonstrated by writing a file to '/system' and rebooting the device. The README also references an external binary ('msmattack') for exploiting CVE-2014-4322, which can further escalate privileges from system to root. The repository contains standard Android project files, resource files, and Java source code. The attack vector is local, requiring code execution on the device. Several URLs are included for further reading and for obtaining the external binary. The exploit is a PoC and does not include a weaponized or easily customizable payload.
This repository is an Android application project implementing a proof-of-concept (PoC) exploit for CVE-2014-7911, a Java deserialization vulnerability in Android that allows privilege escalation to system level. The exploit is based on retme7's PoC but uses a different ROP chain and a heap spray technique (as referenced in the README). The project is structured as a standard Android app, with source code in 'src/AAdroid/os/BinderProxy.java' (defining a Serializable object used in the exploit), resource files under 'res/', and configuration files for building with Eclipse/ADT. The AndroidManifest.xml requests permissions for mock location and external storage, and sets up the main activity. The exploit targets Nexus 5 devices running Android 4.4.4, as specified in the README. No network endpoints or remote attack vectors are present; the exploit is local and requires code execution on the device. The repository does not include a weaponized payload but demonstrates the vulnerability and privilege escalation technique.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.