A vulnerability in Android's WindowManager component allows local attackers to start non-exported and protected activities due to a missing permission check. This flaw enables bypassing intended access controls on activity components, potentially allowing privilege escalation without requiring user interaction or additional execution privileges. The issue affects Android 12L and is tracked as Android ID A-205996115.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (PoC) Android application demonstrating CVE-2021-39749, a vulnerability in Android 12L Beta that allows a non-privileged app to start activities of other apps, including those protected by permissions or not exported, by abusing the TaskFragmentOrganizer API and Binder identity manipulation. The exploit is implemented in two main Java files: FirstActivity.java (which initiates the exploit chain) and SecondActivity.java (which performs the core logic to create a TaskFragment and start arbitrary activities, such as system settings or device shutdown, bypassing normal security checks). The app requires disabling Hidden API checks on the device. The repository includes standard Android project files, resources, and build scripts. The attack vector is local (requires app installation and execution on the target device). The exploit demonstrates privilege escalation and bypass of Android's activity export and permission model, but does not include a weaponized or automated payload beyond the PoC demonstration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.