CVE-2024-0044 is an improper input-validation vulnerability in Android Framework's PackageInstallerService, specifically in createSessionInternal. Insufficient validation of session-related input can enable a local attacker to run as an arbitrary installed application, resulting in elevation of privilege.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
13 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a small standalone proof-of-concept exploit for CVE-2024-0044 affecting Android 12 and 13. It contains one Python script, cve_2024_0044.py, and a README with exploitation guidance and examples. The script is not a scanner; it is an exploitation helper that automates several local ADB-driven steps needed to abuse the vulnerability. Core capability: the exploit helps an operator perform a 'run-as any app' style privilege/context forgery. It pushes a user-supplied APK to /data/local/tmp/, queries the target package UID via 'pm list packages -U', then generates a malicious installer payload saved to payload.txt. That payload is intended to be pasted manually into an adb shell and used with 'pm install -i' to forge installer/session metadata referencing 'victim <uid> ...'. After the operator confirms success, the script creates /data/local/tmp/wa/, creates /data/local/tmp/wa/wa.tar, chmods the directory to 0777, then instructs the operator to manually run 'run-as victim' and tar the target package directory. Finally, it pulls the resulting tar archive back to the host as wa.tar. Repository structure is minimal: README.md documents prerequisites, usage, and examples for extracting WhatsApp, Google Messages, and Samsung contacts data; cve_2024_0044.py implements the exploit workflow. The exploit is interactive and partially manual, relying on ADB shell access and operator confirmation between stages. It is operational rather than fully weaponized: it provides a real exploitation path and data-exfiltration workflow, but payload customization and several critical commands remain manual.
This repository is a small standalone Python exploit utility for CVE-2024-0044 rather than a framework module. It contains one primary code file (`EXPLOITER.py`), a descriptive `README.md`, and a minimal `requirements.txt`. The script is intended to automate exploitation steps against a vulnerable Android device reachable over ADB. Repository structure and purpose: - `EXPLOITER.py`: Main exploit script and only code-bearing file. It handles CLI parsing, ADB connectivity checks, APK transfer, target UID discovery, payload generation, execution of post-exploitation ADB shell commands, and retrieval of an archive from the device. - `README.md`: Describes the tool as an automated exploit for CVE-2024-0044, explains prerequisites and usage, and claims the issue affects Android 12/13 with ADB access. - `requirements.txt`: Lists `requests` and `colorama`, though the script as provided does not actually import or use either package. Main exploit flow in `EXPLOITER.py`: 1. Clears the screen, prints a banner, and shows a warning. 2. Verifies that at least one ADB device is connected using `adb devices`. 3. Accepts two required arguments: target package name (`-p/--package`) and APK path (`-a/--apk`). 4. Pushes the supplied APK to `/data/local/tmp/` on the device with `adb push`. 5. Queries the target app UID using `pm list packages -U | grep <package>` via ADB shell. 6. Generates a crafted multiline installer payload and writes it to `payload.txt`. The payload is designed around `pm install -i` and the victim UID, matching the repository’s claim of exploiting CVE-2024-0044 in Android’s package installation logic. 7. Executes additional ADB shell commands that create `/data/local/tmp/wa/`, set permissions to `0777`, and create a tar archive `wa.tar` containing `com.whatsapp`. 8. Pulls the resulting tarball from the device to the host by streaming it with `adb shell cat` while displaying a progress bar. Capabilities: - Local/ADB-based exploitation assistance for CVE-2024-0044. - Pushes an operator-supplied APK to the target device. - Enumerates the UID of a chosen target package. - Constructs a malicious install command payload intended to run in the context of a victim app. - Performs post-exploitation collection activity by archiving and downloading data associated with a hardcoded target (`com.whatsapp`). Notable observations: - The exploit is local, not network-based; there are no HTTP/S or remote C2 endpoints. - The script does not directly execute the generated `pm install -i` payload from Python; it writes it to `payload.txt` and prints it. The post-generation extraction routine runs regardless, so the automation is incomplete and somewhat inconsistent with the README’s claims. - Although the package name is user-supplied for UID lookup, the extraction stage is hardcoded to `com.whatsapp`, indicating a specific post-exploitation target rather than a fully generic workflow. - Because it includes a concrete payload and post-exploitation data collection logic, it is more than a pure proof of concept, but it is not highly modular or framework-integrated.
This repository contains a Bash script (exploit_cve_2024_0044.sh) and a README.md file. The script is a proof-of-concept exploit for CVE-2024-0044, a high-severity vulnerability affecting Android 12 and 13. The exploit leverages ADB to push a malicious APK to the device, attempts to install it using a crafted payload to escalate privileges, and then uses 'run-as' to archive and exfiltrate the private data of a specified target application. The README provides usage instructions and explains the required parameters. The exploit is local in nature, requiring physical or ADB access to the device, and targets the file system of the Android OS. No network endpoints are contacted; all actions are performed via ADB commands. The main fingerprintable endpoints are file paths on the Android device used for staging and exfiltration of data.
This repository contains a Python exploit script (EXPLOITER.py) targeting CVE-2024-0044, a local privilege escalation vulnerability in Android 12 and 13. The exploit automates the process of pushing a malicious APK to a connected Android device via ADB, extracting the UID of a target app (such as com.whatsapp), generating a custom payload, and executing commands to extract sensitive app data. The script provides a user-friendly command-line interface, checks for ADB connectivity, and manages the full exploitation workflow, including data extraction and progress reporting. The exploit is operational and requires ADB access to the target device. The README.md provides detailed usage instructions, prerequisites, and a disclaimer. The only code file is EXPLOITER.py, and the requirements.txt lists minimal dependencies. The exploit is not part of a larger framework and is focused on local exploitation via ADB.
This repository provides a Bash script ('exploit.sh') and a README for exploiting CVE-2024-0044, a privilege escalation vulnerability in Android's 'run-as' command. The exploit automates the process of pushing a malicious APK to a rooted Android device, extracting the UID of a target application, generating a payload to exploit the vulnerability, and guiding the user through the necessary ADB shell commands to access and extract the application's private data directory. The script is interactive, prompting the user at key steps, and requires the user to provide the target application's package name and the path to the malicious APK. The main attack vector is local, requiring ADB access to the device. Key fingerprintable endpoints include the '/data/local/tmp/' directory (for APK and payload storage), '/data/user/0' (the target data directory), and '/data/local/tmp/wa/wa.tar' (the archive of extracted data). The exploit is operational, providing a working method to escalate privileges and extract sensitive data from Android applications on rooted devices.
The repository 'EvilDroid' is an automated exploit tool targeting CVE-2024-0044, a vulnerability affecting Android devices. The main script, 'evildroid.py', is a Python 3 program that automates the exploitation process by interacting with a connected Android device via ADB (Android Debug Bridge). The tool requires the user to specify a target package name (e.g., 'com.whatsapp') and a malicious APK file. It performs the following steps: checks for ADB connectivity, pushes the APK to the device, retrieves the UID of the target application, generates a payload to exploit the vulnerability, and executes commands to extract sensitive data from the target application's data directory. The extracted data is archived and pulled back to the attacker's machine. The repository includes a README with detailed usage instructions, a requirements.txt for dependencies, and an MIT license. The exploit is operational, requiring a vulnerable device and a malicious APK, and is intended for educational and authorized testing purposes only.
This repository contains a Bash script (exploit_cve_2024_0044.sh) and a README.md file. The script is a proof-of-concept exploit for CVE-2024-0044, a high-severity vulnerability affecting Android 12 and 13. The exploit requires ADB access to a device with USB debugging enabled. It works by pushing a user-supplied APK to the device, crafting a payload to abuse the package manager, and then using the 'run-as' command to archive the data directory of a specified target application (by package name). The resulting archive is then pulled to the attacker's machine. The exploit demonstrates the ability to extract sensitive app data from a vulnerable device. The README provides usage instructions and parameter details. No network endpoints are hardcoded; all operations are performed locally via ADB. The main fingerprintable endpoints are file paths on the Android device used for staging and extracting data.
This repository provides a proof-of-concept exploit for CVE-2024-0044, a local privilege escalation vulnerability in Android 12 and 13. The exploit consists of a Python script (cve_2024_0044.py) and a detailed README.md. The script automates the process of exploiting the vulnerability by pushing a user-supplied APK to the device, generating a payload to install the APK as another app (using a forged install session), and guiding the user through extracting private app data (such as WhatsApp messages, Google Messages, or contacts) from the device. The exploit requires physical or debugging access to the device (via USB or wireless debugging) and does not require root. The README provides step-by-step instructions for extracting data from various apps, including the relevant file paths and commands. The exploit is a POC and requires some manual steps, but demonstrates the impact of the vulnerability by enabling data extraction from protected app directories. No network endpoints are involved; all actions are performed locally on the device via adb.
This repository provides a proof-of-concept exploit for CVE-2024-0044, a local privilege escalation vulnerability in Android 12 and 13. The main file, Exploit.py, is a Python script that automates the exploitation process by interacting with a connected Android device via ADB. The script pushes a user-supplied APK to the device, retrieves the UID of the target app, and generates a payload that abuses the vulnerability to install the APK as another app user. The exploit then guides the user through a series of manual and automated steps to extract private app data (such as WhatsApp data) from the device without requiring root access. The process involves creating a tarball of the target app's data directory and pulling it to the attacker's machine. The repository includes a README with detailed usage instructions and background on the vulnerability. The exploit is not weaponized but provides a functional proof-of-concept for local privilege escalation and data extraction on vulnerable Android devices.
This repository is a proof-of-concept (PoC) exploit for CVE-2024-0044, a high-severity vulnerability in the Android framework affecting versions 12 and 13 prior to the October 2024 security patch. The exploit allows an attacker with adb access to install an arbitrary APK under the UID of any app by abusing the PackageInstaller API and bypassing the original patch. The main exploit logic is implemented in 'app/src/main/java/top/canyie/cve_2024_0044/PoC.java', which forges the installer package name parameter to the PackageInstaller, thereby enabling privilege escalation or data exfiltration attacks. The repository is structured as a minimal Android project, with supporting interface stubs and build files, and is intended for research and demonstration purposes. No network endpoints are hardcoded; the attack is local and requires physical or remote adb access to the device.
This repository contains a Python exploit script (cve_2024_0044.py) targeting CVE-2024-0044, a local privilege escalation vulnerability in Android versions 12, 12L, 13, and 14. The exploit abuses the 'run-as' command to bypass the Android application sandbox, allowing an attacker with ADB shell access to extract private files from any app on the device. The script requires the attacker to provide the target app's package name and any APK file. It pushes the APK to the device, forges a payload to install it under the victim app's UID, and then archives and pulls the victim app's private data to the attacker's machine. The repository also includes a README.md with usage instructions and background information. The exploit is operational and requires local (ADB) access to the device, with endpoints including /data/local/tmp/ and /data/user/0 on the Android filesystem.
This repository provides a Bash script (CVE-2024-0044.sh) that exploits CVE-2024-0044, a privilege escalation vulnerability on Android 12/13. The exploit allows an attacker with ADB access to a device (developer mode enabled) to exfiltrate the private sandbox files of any installed app. The script works by pushing a user-supplied APK to the device, manipulating the package manager to install it with forged parameters, and using the 'run-as' command to tar and extract the target app's data. The exfiltrated data is then pulled to the attacker's machine. The repository is structured simply, with a single exploit script and a README providing usage instructions and context. No network endpoints are involved; all actions are performed locally via ADB.
This repository provides a proof-of-concept exploit targeting CVE-2024-0044, a vulnerability affecting Android 12 and 13. The exploit is designed to escalate privileges or exfiltrate sensitive data from a victim application by leveraging a UID-based attack. The repository contains four files: a README.md with detailed instructions and references, two Metasploit resource scripts (commands.rc and execute_script.rc) to automate payload delivery and handler setup, and a bash script (exploit.sh) that performs the core exploitation steps. The attack flow involves generating a malicious APK payload, setting up a Metasploit handler, delivering the exploit.sh script to the target device (typically via a network download), and executing it to inject the payload into a specified victim app. The exploit requires the attacker to know the victim package name and have a method to execute commands on the device. The endpoints used include example HTTP URLs for script delivery and file paths on the Android filesystem. The exploit is currently a proof-of-concept and not fully weaponized, but demonstrates the core technique for privilege escalation or data exfiltration on vulnerable Android devices.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.