CVE-2018-9493 is a SQL injection vulnerability in the content provider component of the Android Download Manager. The vulnerability arises from improper input validation, allowing a local attacker to inject arbitrary SQL queries. This affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0. No user interaction or additional execution privileges are required for exploitation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) Android application that exploits CVE-2018-9493, a SQL injection vulnerability in Android's Download Provider. The main exploit logic resides in 'app/src/main/java/com/ioactive/downloadProviderDbDumper/MainActivity.java'. The app issues malicious queries to the content provider URI 'content://downloads/my_downloads/' to perform SQL injection and extract sensitive information from the downloads database, including protected columns such as CookieData and ETag. The exploit demonstrates unauthorized access to data by leveraging the vulnerability, and provides a UI to trigger the attack and display results. The repository is structured as a standard Android Studio project, with build scripts, resources, and manifest files. The exploit is operational as a PoC and is not weaponized for automated or remote exploitation, requiring installation and execution on a vulnerable device.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.