Google Chrome versions before 84.0.4147.89 contained a Cross-Origin Resource Sharing (CORS) policy bypass. A remote attacker could use a crafted HTML page to circumvent same-origin restrictions and leak data from another origin.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a comprehensive proof-of-concept (PoC) toolkit for exploiting Man-in-the-Disk (MitD) and Man-in-the-Middle (MitM) vulnerabilities in WhatsApp for Android, specifically targeting CVE-2020-6516 (Chrome) and CVE-2021-24027 (WhatsApp). The exploit chain involves: 1. **Phishing and CORS Bypass**: The attacker sends a phishing message to the victim via WhatsApp, containing a malicious HTML file. When opened, this file exploits a CORS bypass to read serialized TLS session data from the victim's device and exfiltrate it to an attacker-controlled HTTP server. 2. **Session Key Extraction and MitM**: The attacker uses the exfiltrated session data to perform a MitM attack on WhatsApp's TLS connections. The repository provides custom OpenSSL and BoringSSL patches and scripts to facilitate this, including tools for converting and using the session data. 3. **ZIP Path Traversal and Code Execution**: The attacker delivers a ZIP file with a path traversal payload to WhatsApp, overwriting the libwhatsapp.so library. This enables arbitrary code execution in the context of the WhatsApp app. 4. **Key Extraction**: Custom payloads (Java, C, and shell scripts) are used to extract cryptographic keys (Noise keys, prekeys, etc.) from the victim's WhatsApp installation, enabling further compromise. The repository is well-structured, with directories for Frida scripts (for hooking and phishing), TLS 1.2 and 1.3 MitM toolsets (including OpenSSL/BoringSSL patches and key extraction utilities), and various helper scripts. It is a highly advanced, multi-stage exploit toolkit requiring significant attacker setup and access, but demonstrates a full attack chain from initial phishing to complete compromise of WhatsApp's cryptographic secrets on Android devices.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.