A vulnerability in the setDisplayPadding function of WallpaperManagerService.java in Android 12 allows a local attacker to cause a persistent denial of service. The issue arises from improper input validation, enabling an attacker to provide crafted input that disrupts the normal operation of the service. No user interaction or additional privileges are required for exploitation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains an Android application called 'Wallbreak' that demonstrates two high-severity permanent denial-of-service (PDoS) vulnerabilities in Android's WallpaperManagerService: CVE-2021-39670 and CVE-2021-39690. The app provides two main exploit functions: 1. The 'Stream Exploit' (CVE-2021-39670) uses a very large PNG image, extracted from an asset ZIP, and sets it as the device wallpaper using the setStream API. This exhausts device memory, causing the system to crash and reboot repeatedly. 2. The 'Padding Exploit' (CVE-2021-39690) sets an extremely large display padding value via WallpaperManager.setDisplayPadding, which can crash the SurfaceFlinger service or exhaust memory, especially on Pixel devices with animated live wallpapers running Android P or higher. The repository is structured as a standard Android Studio project, with the main exploit logic implemented in 'app/src/main/java/me/sithi/wallbreak/MainActivity.java'. The app requires the SET_WALLPAPER and SET_WALLPAPER_HINTS permissions. The exploits are triggered via UI buttons in the app, and the payloads are delivered locally on the device. The README provides detailed context, including links to the CVEs and patch information. No network endpoints are involved; the attack is purely local. The exploit is a proof-of-concept and does not include weaponized or remotely-triggerable payloads.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.