CVE-2019-2196 is a SQL injection vulnerability in the Download Provider component of Android versions 8.0, 8.1, 9, and 10. The vulnerability allows a local attacker to inject arbitrary SQL queries into the Download Provider, potentially leading to unauthorized access to sensitive information stored in the database. No additional execution privileges or user interaction are required for exploitation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2019-2196, a SQL injection vulnerability in the Android (AOSP) Download Provider's sort parameter. The main exploit is implemented as an Android application (Java) in 'app/src/main/java/com/ioactive/downloadProviderDbDumperSQLiLimit/MainActivity.java'. The app leverages the ContentResolver to interact with the Download Provider content provider at 'content://downloads/my_downloads/'. By crafting SQL expressions in the sort parameter, the app performs SQL injection to extract sensitive data from the downloads and request_headers tables. The exploit automates the process of extracting data byte-by-byte using binary search and other techniques, and displays the results in the app's UI. The repository includes standard Android project files, build scripts, and resources. The exploit is operational as a PoC and demonstrates the impact of the vulnerability, but does not include weaponized or customizable payloads. The main attack vector is local, requiring the app to be installed and executed on a vulnerable Android device.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.