CVE-2020-0022, known as BlueFrag, is an out-of-bounds write vulnerability in Android's Bluetooth packet-fragment reassembly logic, specifically the reassemble_and_dispatch function in packet_fragmenter.cc. Packet-length calculation omits an offset, resulting in incorrect bounds handling and a write beyond the intended buffer. The issue affects Android 8.0, 8.1, 9, and 10.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository implements a Bluetooth-based exploit for CVE-2020-0022 (BlueFrag) targeting Android 8/9 Bluetooth stack, written in C with modular components for connection management, memory disclosure, and memory corruption leading to control-flow hijack. Key components: - src/exploit.c: Main orchestrator. Takes victim BDADDR, repeatedly (1) crashes target to improve heap state, (2) leaks libandroid_runtime.so base (ASLR defeat), (3) leaks an address of an attacker-controlled sprayed heap chunk, (4) corrupts a libchrome vtable to redirect execution to the sprayed JOP payload. Includes retry loops (REPEAT_COUNT=7) and interactive retry prompt. - src/bluetooth.c + include/bluetooth.h: BlueZ-based HCI/L2CAP primitives. Uses raw HCI socket and L2CAP echo traffic; manipulates SSP mode and restarts adapter via system("sudo btmgmt...", "sudo hciconfig..."). Sends spoofed HCI ACL/L2CAP headers and receives echo responses with identifier matching. - src/leak.c + include/leak.h: Implements two leak strategies: * leak_simple: triggers a memcpy underflow/overflow style leak by sending two crafted fragments (first/second packet sizes around 66 bytes) and reading back an echo response. * leak_fancy / leak_libandroid_runtime_base / leak_controlled_payload_address: heap spray and pattern matching to locate leaked pointers. Uses egg marker (0xDEADBEEF...); sprays 512-byte chunks and searches for leaked vtable pointers to compute libandroid_runtime base using fixed offsets. - src/smash.c + include/smash.h: Two-stage corruption: * smash_crash_target: sends repeated crafted packets (size ~140) to crash Bluetooth on target. * smash_corrupt_libchrome_vtable: sprays overwrite data (fake vtable address repeated) via many connections/packets to corrupt a libchrome vtable pointer to point at the attacker-controlled payload address. - include/libandroid_runtime_constants.h: Autogenerated offsets for two ASLR leak anchors and key gadgets/functions in libandroid_runtime.so (DOUBLE_CALL, X21_ADDER, CALLER, execv, fork). These are combined with leaked base to form absolute addresses. Payload/JOP: - The exploit crafts a JOP table in the sprayed heap chunk. The chain uses libandroid_runtime gadgets to call fork then execv("/bin/sh", ["/bin/sh","-c",<command>,NULL]). Default command is a persistent background loop (not a network shell). The repo explicitly notes Pixel 3 XL restrictions preventing fork/execv from Bluetooth context, and therefore stops short of more weaponizable post-exploitation. Auxiliary tooling: - ghidra_scripts/ProcessLibandroidRuntime.java and Jopperhimer.java: Ghidra scripts to extract gadget/function offsets and generate header defines to ease porting. - jop_experiment/ and map_experiment/: Android NDK helper binaries to simulate the JOP chain and study std::unordered_map/heap layouts relevant to the leak. - notes/: detailed development notes, gadget lists, crash/leak targets, and memcpy tracing used to reason about the memory disclosure primitive. Overall, this is a real exploit implementation (not just detection) that achieves ASLR leak + PC control and constructs a command-execution JOP payload, with operational reliability features (sprays, retries, adapter restarts) but limited by target-side policy mitigations on the tested device.
This repository contains two Python scripts (polo_leak.py and polo_leak_v2.py) and a detailed README.md. The scripts are proof-of-concept exploits for CVE-2020-0022 (BlueFrag), targeting Bouygues BBox Miami Android TV devices running Android 8.0 on ARM32 Cortex A9. The exploit leverages a zero-length memcpy vulnerability in the Bluetooth stack to leak uninitialized memory via L2CAP echo responses. The README provides extensive technical background, usage instructions, and details on constructing a ROP chain to achieve code execution via the Bluetooth daemon. The scripts require the target's Bluetooth MAC address and optionally ADB access for further interaction. The exploit is capable of leaking memory and, with a crafted payload, executing arbitrary shell commands on the target device. The repository is structured for research and demonstration purposes, with logging and verbose output for analysis of the exploit process.
This repository contains a proof-of-concept (PoC) exploit for CVE-2020-0022, a vulnerability in the Bluetooth stack of certain Android devices. The main exploit code is in 'poc.c', which is a C program that establishes a raw L2CAP connection to a target Bluetooth device (specified by its MAC address) and sends specially crafted packets to trigger a crash in the target's Bluetooth stack. The exploit is designed to be run on a Linux system with Bluetooth hardware and the BlueZ stack, and has been tested on devices such as the Raspberry Pi 3B. The README provides usage instructions and notes on device compatibility and stability. The attack vector is network-based, specifically over Bluetooth, and the only required endpoint is the MAC address of the target device. The exploit demonstrates a denial-of-service condition and does not provide remote code execution or privilege escalation.
This repository is a full exploit implementation for CVE-2020-0022 (BlueFrag), a critical Bluetooth RCE vulnerability affecting Android 8.0 and 9.0. The exploit is written in C and is modular, with separate components for Bluetooth communication, memory leaks, heap spraying, and the final exploitation step. The main entry point is 'src/exploit.c', which orchestrates the attack: it connects to the target device over Bluetooth L2CAP, leaks the base address of 'libandroid_runtime.so' (defeating ASLR), leaks a controlled memory address for payload injection, and then corrupts a vtable in the target's memory to hijack control flow. The payload is a JOP chain that ultimately executes arbitrary shell commands on the target device. The repository also includes Ghidra scripts for extracting gadget offsets from the target library, and two Android NDK projects ('jop_experiment' and 'map_experiment') for simulating and analyzing the exploit's memory manipulation techniques. The exploit is operational and can be used to achieve RCE on vulnerable Android devices, but is not fully weaponized (e.g., it does not include universal payloads or root escalation).
This repository provides a set of proof-of-concept and operational exploit scripts for CVE-2020-0022 (BlueFrag), a critical Bluetooth remote code execution vulnerability affecting Android 8.0 and 9.0 devices. The main exploit (cve_2020_0022/exploit.py) is a Python script that interacts directly with Bluetooth HCI and L2CAP sockets to craft and send malicious packets to a target device, exploiting a heap overflow to achieve remote code execution. The exploit requires the attacker's Bluetooth adapter to be in a specific state and uses several helper scripts for memory leak and crash testing (fancy_leak.py, simple_leak.py, simple_crash.py). The payload is a shell command that opens a reverse shell on the target using toybox nc and /system/bin/sh. The repository also includes a C proof-of-concept (poc.c) for low-level packet crafting. The exploit is zero-click, requiring no user interaction on the target, and is highly effective against unpatched Android 8.0/9.0 devices with Bluetooth enabled. The scripts reference and use several system files and libraries on the target, such as /system/lib64/libicuuc.so, /system/lib64/libc.so, and /system/bin/sh, and rely on knowledge of their memory addresses, which can be leaked using the included scripts. Overall, the repository demonstrates a sophisticated Bluetooth-based attack vector and provides operational exploit code for researchers and penetration testers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A mobile phone Bluetooth implementation vulnerability where incorrect packet length calculation leads to an out-of-bounds write.
A mobile phone Bluetooth implementation vulnerability where incorrect packet length calculation leads to an out-of-bounds write.
A vulnerability chain in a mobile phone Bluetooth implementation where an incorrect packet-length calculation omits an offset, resulting in an out-of-bounds write.
An out-of-bounds write in a mobile phone Bluetooth implementation due to incorrect packet length calculation (missing offset).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.