Janus is an elevation of privilege vulnerability in Android's application handling that affects Android 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, and 8.0. The flaw allows an attacker to modify an APK file without invalidating its signature under the v1 APK Signature Scheme. In practice, a crafted APK can preserve the original signed contents expected by signature verification while introducing attacker-controlled executable content, enabling installation or replacement of an application that appears to retain a valid signature. This can be used to overwrite an already installed application and abuse that application's existing privileges, resulting in elevation of privilege on affected devices.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Python script, 'exploit.py', which is a proof-of-concept tool for injecting a DEX file (such as one extracted from WhatsApp) into a target APK. The script operates locally and requires the user to provide a DEX file, a target APK, and an output filename. The process involves modifying the APK's central directory to account for the new DEX file, updating checksums, and writing the combined file as a new APK. The script is intended for use in scenarios where an attacker can manipulate APK files, potentially to bypass signature or integrity checks and inject arbitrary code. The repository does not target a specific CVE but is relevant to Android APK/Dex manipulation, with a focus on WhatsApp as an example. The structure is simple, with only one Python file and no external dependencies beyond standard Python libraries and the required APK files.
This repository demonstrates two Android security threats: (1) abuse of exported broadcast receivers with weak custom permission protection, and (2) clipboard snooping by background apps. The main focus is on the 'Exposed BroadCastReceiver Threat' directory, which contains both a 'victim app' (simulating a device booster utility) and an 'attacker app' (broadcast spammer). The victim app exposes a broadcast receiver (com.victimapp.MySensitiveReceiver) that performs sensitive actions (vibration, toast, app launch) when triggered by a broadcast intent with action 'com.victimapp.CLEANUP'. Although the receiver is protected by a custom permission (com.victimapp.SENSITIVE_PERMISSION), this is set to 'normal' protection level, allowing any app to declare the same permission and send broadcasts. The attacker app exploits this by repeatedly sending crafted intents to the receiver, causing the victim app to execute privileged actions without proper authorization. The exploit is operational and demonstrates a real-world Android security anti-pattern. The repository also contains a clipboard snooper PoC in the 'Clipboard_threat/backgroundApp' directory, which logs clipboard contents to a file in the Downloads directory, but the main exploit of interest is the broadcast receiver abuse.
This repository contains a single Metasploit module (modules/exploits/android/local/janus.rb) that exploits the Android Janus vulnerability (CVE-2017-13156). The exploit targets Android devices running versions 5.1.1 to 8.0.0 that have not received the December 2017 security patch and are using APKs signed with the v1 signature scheme. The module works by injecting a payload (such as android/meterpreter/reverse_tcp) into an existing APK, uploading the backdoored APK to the device, and triggering an update installation. This allows the attacker to gain code execution in the context of the target app while preserving its data and signature. The exploit requires a session on the device (e.g., via meterpreter) and knowledge of the target package name. The code is written in Ruby and is structured as a typical Metasploit local exploit module, with functions for checking vulnerability, infecting APKs, and executing the exploit. No network endpoints are hardcoded; the main fingerprintable artifacts are file paths on the Android device.
This repository is a proof-of-concept (POC) for exploiting the Android Janus vulnerability (CVE-2017-13156), which allows attackers to inject a malicious DEX file into a legitimate APK without invalidating its signature. The repository contains an Android app project (JanusApp), various DEX and APK files, and both Python (janus.py) and Java (Janus.jar) tools to perform the injection. The README provides detailed steps for modifying an APK, including decompiling, editing smali code, repackaging, and using the provided tools to create a new APK that bypasses signature checks. The exploit targets Android versions 5.0 to 8.0 and demonstrates the ability to execute arbitrary code in the context of a signed app. The attack vector is local, requiring the attacker to have access to the APK and the ability to install the resulting malicious APK on a vulnerable device. No network endpoints or remote services are involved; all manipulation is performed on local files.
This repository is a toolkit for exploiting the Janus vulnerability (CVE-2017-13156) in Android. It contains tools written in Python and Go for injecting arbitrary code or data (such as a DEX file) into APK files without invalidating the APK Signature v1. The main exploit scripts are 'python3/janus.py' and 'golang/main.go', both of which manipulate the APK's ZIP structure to prepend custom data and adjust ZIP directory offsets, optionally correcting DEX checksums to ensure validity. The toolkit also includes helper scripts: 'extract_dex.py' for extracting DEX files from already injected APKs, and 'manifest_dummy.py' for generating dummy Java classes and manifest tags to assist with Android Studio projects. The exploit targets Android versions 5.1.1 through 8.0 (pre-Nougat), where the Janus vulnerability allows attackers to modify APKs without breaking their cryptographic signatures. The attack vector is local, requiring access to APK files for modification. No network endpoints or remote services are involved; all operations are performed on local files. The repository is structured with clear separation between Go and Python implementations, and includes Java templates for dummy class generation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in Android's APK signature verification (CVE-2017-13156, Janus) allows attackers to modify APK files without invalidating the signature, enabling installation of malicious code as a trusted app.
An Android APK signature verification bypass and privilege escalation vulnerability in the v1 APK Signature Scheme that allows a forged APK to bypass signature checks and overwrite installed apps, enabling code execution with the target app's privileges.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.