CVE-2024-31317 is an unsafe deserialization vulnerability in multiple functions of Android's ZygoteProcess.java. An actor with WRITE_SECURE_SETTINGS can exploit the flaw to execute code as any application, resulting in local privilege escalation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
15 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a practical research and testing workspace around CVE-2024-31317 on Android, not a standalone exploit implementation by itself. The core exploit binary is external (referenced as a Rust project/binary named rust_exploit or android_31317_exploit_rs), while this repo documents exploitation mechanics, target applicability, emulator instrumentation, and device-specific validation on a Sharp AQUOS zero2 (SH-01M). Repository structure: most files are Markdown analysis documents explaining the Zygote injection primitive, required arguments, SELinux impersonation, device findings, and follow-on privilege-escalation options. The executable content is mainly Bash automation: quick_test.sh and test_exploit.sh drive ADB-based exploit attempts against a connected device; dump_block.sh and dump_payload.sh enumerate privileged files, partitions, TrustZone/QSEE nodes, and OEM lock HAL artifacts after gaining execution; emulator/install.sh plus emulator/zygote.patch support building a debug AOSP emulator to study Zygote behavior. Main exploit capability: abuse of the hidden_api_blacklist_exemptions setting to inject forged Zygote arguments, allowing attacker-controlled process creation under selected Android identities such as shell (UID 2000) or system/system_app (UID 1000). The documented successful technique on Android 12+ uses --invoke-with and a shell wrapper that brute-forces writes of its PID to file descriptors 3-9 so Zygote accepts the wrapped child instead of killing it. Demonstrated post-exploitation actions include command execution via /system/bin/log, service call oem_lock interactions, and hardware/security boundary probing. The repo clearly targets local exploitation on Android devices before the June 2024 patch level, with the SH-01M as the primary validated target. It is not merely a detector: it contains operational test harnesses and post-exploitation scripts, though the actual exploit binary must be obtained/built separately. The included external_pocs directory is only analytical guidance for chaining CVE-2024-31317 into kernel root via Binder or KGSL vulnerabilities; those external exploits are not included here.
Repository is a standalone Android exploit toolkit for CVE-2024-31317, not tied to a common exploit framework. It contains 6 files: a Python orchestrator (cve_2024_31317.py), a Java payload (Hijack.java), a minimal AndroidManifest.xml for the carrier APK, a setup helper script, README, and license. The overall purpose is to exploit Android Zygote-related behavior to execute code under a chosen app UID, then use that access to extract private app data or provide shell access. Main components: (1) cve_2024_31317.py is the primary entry point and operator tool. It handles ADB communication, device/version/patch checks, AFU unlock polling, host dependency checks, APK build/install workflow, retry/reboot/recovery logic, chaining across multiple target packages, and user-facing modes such as extraction, interactive shell, persistent shell, vulnerability check, app listing, and recovery. (2) Hijack.java is the actual post-exploitation payload executed on-device. It accepts a target package and ports, kills leftover same-UID processes by walking /proc, optionally spawns a background tar-to-netcat exfiltration process for /data/user/0/<package>, optionally creates a FIFO-backed persistent command server, and always supports a primary TCP bind shell by wiring a socket to /system/bin/sh. (3) AndroidManifest.xml defines the carrier APK package com.example.hijackpayload. (4) setup.sh validates required host tools. Exploit capabilities are substantial and clearly offensive: it can expose a bind shell on a configurable TCP port (default 8888), create a persistent single-port shell service, and exfiltrate an app's private data directory as a tar stream over netcat. The Python wrapper also includes operational conveniences such as retries, multi-target chaining, reboot scheduling, and recovery/reset support. Because the payloads are hardcoded but functional and configurable by arguments/ports, the repository is best classified as OPERATIONAL rather than a simple POC. Fingerprintable targets/endpoints are mostly local Android paths and TCP listeners rather than external C2 infrastructure. Notable artifacts include /data/user/0/<targetPackage>, FIFO files named .zs_<port> inside the target app directory, /proc and /proc/<pid>/status for process enumeration, /system/bin/sh for command execution, default bind shell listener 0.0.0.0:8888, configurable extraction/persistence netcat listeners, and Android system properties queried via adb shell getprop. No hardcoded external internet domains or remote IPs were found.
Repository purpose: an educational Android security lab demonstrating CVE-2024-31317 (Zygote argument injection via hidden_api_blacklist_exemptions) to escalate a malicious app to SYSTEM (UID 1000) and then access another app’s private data and exfiltrate it to a dashboard. Key components (apps/): - apps/FlashlightPro/: the malicious “innocent” flashlight app. MainActivity starts ExploitService in the background. ExploitService sleeps 5 seconds (anti-suspicion), then writes a multiline payload into Settings.Global "hidden_api_blacklist_exemptions". The payload includes Zygote args such as --setuid=1000/--setgid=1000 and an --invoke-with clause that runs: "am start-foreground-service -n com.example.monitorservice/.MonitorService;". It then launches the Android Settings app (Settings.ACTION_SETTINGS) to help trigger the chain. - apps/MonitorService/: the post-exploitation SYSTEM-level service intended to be started by the injected Zygote command. On create, it logs its UID, checks privileges by reading /data/system/packages.xml, and attempts to read the victim key file. It periodically (every 2 seconds) calls readNewMessages() and exfiltrates via HTTP POST to a hardcoded dashboard URL (http://10.0.2.2:5000/steal). Note: extractMessages() is currently a stub returning an empty list, so the exfiltration loop won’t send real messages unless implemented. - apps/SecureChat/: the victim app. A simple Jetpack Compose chat app storing messages in a Room SQLite DB (securechat.db). It “encrypts” message content using a demo XOR + Base64 scheme (Encryption.kt) with a hardcoded key (not actually stored at /files/key in this codebase), but the MonitorService is written to look for a key file at /data/data/com.example.securechat/files/key. Exploit capabilities: - Local privilege escalation on vulnerable Android builds by abusing missing sanitization in Zygote setting parsing (newline injection into hidden_api_blacklist_exemptions). - Spawns/starts an attacker-controlled Android Service (MonitorService) intended to run as SYSTEM (UID/GID 1000) using injected Zygote arguments and Activity Manager invocation. - Post-exploitation file access attempts to system and cross-app private paths under /data/system and /data/data. - Network exfiltration over HTTP to a local dashboard endpoint (emulator host loopback). Notable permissions/assumptions: - FlashlightPro requests WRITE_SECURE_SETTINGS (called out in README as auto-granted on vulnerable systems in this lab), plus INTERNET. - MonitorService is exported/enabled and designed to run persistently (START_STICKY). Overall, this is an operational lab PoC chain (not just detection): it includes a privilege-escalation payload and an exfiltration client, but the message extraction from SQLite is not implemented in the provided MonitorService code.
Repository purpose: a set of Android shell PoCs for CVE-2024-31317, split by Android version (11-, 12, 13). The exploit technique is to craft a large, precisely padded payload and write it into the global setting `hidden_api_blacklist_exemptions`, then trigger processing by force-stopping and launching the Settings app (`android.settings.SETTINGS`). The injected content resembles Zygote argument injection and includes `--invoke-with /system/bin/logwrapper echo zYg0te $(id) #` to demonstrate command execution; success is verified by searching logcat for `zYg0te`. Structure: - `CVE-2024-31317-android11-.sh`: simpler payload string with embedded newlines/commas and an injection command; writes `/data/local/tmp/payload.txt`, sets the global setting, launches Settings. - `CVE-2024-31317-android12.sh`: constructs an 8192-byte-aligned payload using many newlines and ‘A’ padding, then appends the injection command and comma padding. - `CVE-2024-31317-android13.sh`: similar to Android 12 but includes explicit byte-offset verification (checks that the byte at the computed offset equals ASCII '9') to ensure the malicious command begins at the intended boundary. - `starter.sh`/`starter.cmd`: host-side helpers that `adb push` the chosen script to `/data/local/tmp/`, chmod it, and execute it. - `cleanup.sh`/`cleanup.cmd`: host-side cleanup to remove `/data/local/tmp/payload.txt` and reset `hidden_api_blacklist_exemptions` to null; the exploit scripts also drop an on-device `/data/local/tmp/cleanup.sh`. Notable operational risk: the scripts warn that failing to clean up before reboot may render the device unbootable (DoS) due to the persistent poisoned global setting.
Repository purpose: an educational PoC/deployer for CVE-2024-31317 (Android 9–13) demonstrating command injection into Zygote startup arguments via the global setting `hidden_api_blacklist_exemptions` (newline injection), then using `--invoke-with` to execute a payload. Structure (6 files): - `README.md`: High-level description, affected versions, and step-by-step exploitation workflow using ADB. Shows how to compile, push the payload to `/data/local/tmp/`, inject the malicious setting value containing `L*\n--invoke-with ...`, and trigger by restarting services. Uses example callback `192.168.1.100:4444` and `nc -lvnp 4444` listener. - `VULNERABILITY_ANALYSIS.md`: Technical write-up explaining Zygote, root cause (missing newline escaping), exploitation stages, and basic detection/mitigation notes. - `compile.sh`: Builds a static ARM64 binary using Android NDK clang (`aarch64-linux-android21-clang`) into `bin/reverse_shell_arm64`. Requires `NDK_PATH`. - `reverse_shell.c`: The actual payload. Takes `<host> <port>`, connects via TCP with up to 3 retries, dup2’s the socket to stdin/stdout/stderr, and execs `/system/bin/sh -i`. - `payloads/payload_android_9-11.txt` and `payloads/payload_android_12-13.txt`: Preformatted injected strings for different Android versions; 12–13 wraps execution with `/system/bin/sh -c` and escaping. Exploit capabilities: - Achieves arbitrary command execution in Zygote context on vulnerable Android versions when attacker can set the secure global setting (requires `WRITE_SECURE_SETTINGS`). - Deploys and runs a native reverse shell that provides an interactive `/system/bin/sh` session back to an operator-controlled host/port. Notable constraints/assumptions: - This repo does not include an app to obtain `WRITE_SECURE_SETTINGS`; it assumes the operator already has that capability (commonly via ADB/dev settings or privileged context). - Payload compilation is ARM64-focused; no multi-arch build logic is included.
This repository provides a working exploit for CVE-2024-31317, a command injection vulnerability in Android 9-13's Zygote process. The exploit leverages the 'hidden_api_blacklist_exemptions' global setting, which, when improperly sanitized, allows an attacker with WRITE_SECURE_SETTINGS permission to inject commands that are executed with system privileges. The repository includes: - A C source file (reverse_shell.c) for a reverse shell payload, which connects back to an attacker-specified IP and port, providing a shell on the device. - A bash script (compile.sh) to compile the payload for ARM64 using the Android NDK. - Predefined payload templates for Android 9-11 and 12-13, which show how to inject the payload via the vulnerable setting. - Documentation (README.md, VULNERABILITY_ANALYSIS.md) detailing the vulnerability, exploitation steps, and mitigation. The exploit requires local access (typically via ADB) and the ability to set global settings and push binaries. The main attack flow is: compile the payload, push it to the device, inject the payload path and attacker IP/port into the vulnerable setting, and restart the system server to trigger execution. The result is a reverse shell as the system user. No external network endpoints are hardcoded; the attacker supplies their own IP and port. The repository is well-structured for educational and research purposes, with clear separation of code, payloads, and documentation.
This repository provides a Python-based exploit for CVE-2024-31317, a command injection vulnerability in Android's Zygote process. The main script, 'CVE-2024-31317-Debuggable.py', orchestrates the attack by leveraging ADB to interact with a connected Android device. It ensures a helper APK is installed, extracts a runtime sequence value (startSeq) via JDWP, and then injects malicious zygote arguments through the 'hidden_api_blacklist_exemptions' system setting. This enables the 'debuggable' flag for any target app, allowing the attacker to attach a JDWP debugger and inspect or manipulate the app process. The exploit supports both auto-detection and hardcoded configuration modes for targeting apps. The included 'jdwplib.py' is a minimal JDWP client library used for interacting with the Java Debug Wire Protocol. The exploit is operational and provides a working method to enable debugging on any app on a vulnerable Android device, but does not provide root access. The repository is well-structured, with clear separation between the exploit logic, JDWP communication, and documentation.
This repository is a comprehensive Android application and native code suite designed to exploit CVE-2024-31317, a privilege escalation vulnerability in the Android Zygote process. The project consists of an Android app (Java/Kotlin) with a user interface for configuring and launching the exploit, as well as native C binaries (zygote_term, zygote_nc, etc.) that interact directly with the Zygote process and system sockets. Key capabilities include: - Arbitrary uid/gid/selinux context/groups injection via Zygote process manipulation. - Reverse shell and interactive shell access through local TCP sockets (default 127.0.0.1:9981). - Application data extraction via a custom socket protocol (default 127.0.0.1:56423). - Zygote log monitoring and streaming via a local server (127.0.0.1:13568). - Integration with Termux terminal emulator for advanced shell interaction. - Payload deployment and execution via Shizuku permission, allowing privileged operations without root. The repository is structured as a full Android Studio project, with the main app under 'app/', native code under 'app/src/main/jni/', and a bundled terminal emulator under 'terminal-emulator/'. The exploit is operational and provides a user-friendly interface for configuring and launching privilege escalation attacks on vulnerable Android devices. The code is not a simple PoC but a functional, weaponized tool for local privilege escalation, data extraction, and shell access on Android 9-13 devices vulnerable to CVE-2024-31317.
This repository provides a proof-of-concept exploit for CVE-2024-31317, a Zygote injection vulnerability affecting Android 12+ devices prior to the June 2024 security patch. The exploit's main goal is to remove a profile owner (such as Google's Family Link) and all associated device restrictions, effectively regaining full control over a supervised device. The repository contains a C++ source file (zygotroll.cpp) that crafts and sends Binder transactions to the device_policy service, removing user restrictions and clearing the profile owner. A shell script (payload.sh) is used to prepare and inject the payload, leveraging the Zygote process. The README.md provides detailed build and usage instructions, including how to customize the exploit for a specific device and profile owner. The exploit requires local access to the device, developer mode enabled, and the ability to install custom binaries and APKs. No remote or network attack vector is present; all actions are performed locally on the device. The exploit is a POC and requires manual configuration for each target device.
This repository provides a full proof-of-concept exploit kit for CVE-2024-31317, a command injection vulnerability in the Android Zygote process affecting Android 9 through 13. The kit includes: - A Bash deployment script (Android_Zygote_Research_Kit.sh) that generates all necessary files and guides the user through the exploitation process. - Two payload files (payload91011.txt for Android 9-11, payload1213.txt for Android 12-13) that must be edited to include the attacker's IP address. These payloads exploit the Zygote vulnerability by injecting commands via the hidden_api_blacklist_exemptions system setting. - A C program (reverse_shell.c) that acts as a TCP server listening on port 9981, designed to receive a reverse shell from the exploited device. - A compile script (compile.sh) to build the reverse shell server. - Documentation files (README.md, README.txt, CVE-2024-31317.txt) providing technical analysis, usage instructions, and vulnerability background. The exploit requires the attacker to have WRITE_SECURE_SETTINGS permission on the target device and for the device to be unpatched (pre-June 2024 security update). The attack is performed locally on the device, but the payload establishes a network connection back to the attacker's server. The main attack vector is local privilege escalation via command injection, with a network component for remote shell access. The repository is well-structured, with clear separation between deployment, payload, and documentation files.
This repository provides an operational exploit kit for CVE-2024-31317, a command injection vulnerability in the Android Zygote process affecting Android 9 through 13. The main file, 'Android_Zygote_Research_Kit.sh', is a Bash script that generates all necessary components for the exploit, including: - 'reverse_shell.c': A C program implementing a TCP reverse shell listener on port 9981. - 'payload.txt': A payload file containing a command injection string that, when written to the 'hidden_api_blacklist_exemptions' global setting on a vulnerable Android device, causes the device to connect back to the attacker's server and execute shell commands. - 'compile.sh': A script to compile the C reverse shell program. - 'CVE-2024-31317.txt': A technical analysis of the vulnerability. - 'README.txt': Detailed usage instructions. The exploit requires the attacker to have WRITE_SECURE_SETTINGS permission on the target device. The attacker uploads the payload to the device, sets the global setting to the payload, and triggers the Zygote process to execute the injected command. The payload connects to the attacker's server (on port 9981) and provides a shell. The exploit is operational and provides a working reverse shell, but requires some manual steps and configuration (such as setting the attacker's IP in the payload). No network endpoints are hardcoded except for the port; the attacker must specify their own IP. The repository is well-structured, with clear separation between exploit logic, payload, and documentation.
This repository documents and explains the exploitation of CVE-2024-31317, a critical Android vulnerability that allows unprivileged apps to escalate privileges by injecting arguments into the Zygote process via the 'hidden_api_blacklist_exemptions' global setting. The repository is primarily research-focused, containing detailed markdown documentation (README.md, explanation.md, arguments.md, selinux.md) and an emulator setup (emulator/ directory) for testing and debugging the exploit. The core exploit involves crafting a payload string that, when set in the global settings, is parsed by Zygote as command-line arguments, enabling the attacker to spawn processes as 'system' or 'shell' with arbitrary SELinux context. The repository includes a patch file (zygote.patch) for enhanced debugging in emulator environments and a shell script (install.sh) for setting up a custom Android emulator image. No ready-to-run exploit code is present, but the documentation provides all necessary details for constructing and deploying the exploit on vulnerable Android devices.
This repository is a Python-based exploit toolkit targeting the Android Zygote injection vulnerability (CVE-2024-31317). The exploit is operational and is designed to be run from a host computer with ADB and USB debugging enabled on the target Android device. The main entry point is 'zygote_injection_toolkit/__main__.py', which orchestrates a two-stage exploit process: - Stage 1 (stage1.py): Connects to the Android device via ADB, checks for vulnerability, and exploits the zygote injection flaw to execute a reverse shell as the 'system' user on port 1234. It also manipulates system settings to attempt to enable OEM unlocking, potentially bypassing carrier restrictions. - Stage 2 (stage2.py): Connects to the reverse shell and interacts with the Android 'OemLockService' via AIDL, attempting to further manipulate OEM unlock settings and verify the device's unlock status. The toolkit includes utilities for parsing Android Parcels and SELinux context files, which aid in privilege escalation and context discovery. The exploit does not provide root access but allows code execution as the 'system' user, enabling backup and manipulation of private app data and system settings. The exploit is effective only on devices not updated to the June 1, 2024 security patch. The payload is a reverse shell, and the main network endpoint is 127.0.0.1:1234 on the device. The code is modular, with clear separation between exploitation logic, AIDL interface parsing, and SELinux context analysis.
This repository is an Android application project designed to exploit the 'hidden_api_blacklist_exemptions' global setting on Android devices. The main exploit logic resides in MainActivity.java, where two buttons allow the user to set the payload or a wildcard ('*') to the 'hidden_api_blacklist_exemptions' setting via the content provider 'content://settings/global'. The payload is a carefully crafted string that includes process arguments and a reference to a native library (exp.so), which is intended to be loaded for further exploitation. The exploit requires the WRITE_SECURE_SETTINGS permission, which is typically restricted to system apps or devices with elevated privileges. The repository does not include the native payload (exp.so), but the Java code demonstrates the method for bypassing Android's hidden API restrictions and potentially escalating privileges by loading custom native code. The project structure is a standard Android Studio project with build scripts, resources, and configuration files.
This repository contains a working exploit for CVE-2024-31317, a command injection vulnerability in the Android Zygote process via the 'hidden_api_blacklist_exemptions' global setting. The exploit is implemented as an Android application (Java) that, when granted the WRITE_SECURE_SETTINGS permission (typically via ADB or engineering mode), injects a specially crafted payload into the global settings database. This payload leverages newlines and command-line arguments to inject arbitrary parameters into Zygote, including the ability to execute custom binaries or shell commands as the system user. The exploit supports both Android 11 and below (simple injection) and Android 12+ (with a bypass for the new parser using buffer overflows and timing). The main exploit logic is in MainActivity.java, with the payload constructed in the Get_Payload() function. The repository includes standard Android project files, build scripts, and resources, but the core exploit is in the app module. No network endpoints are hardcoded, but the payload can be customized to execute network commands (e.g., using netcat). The exploit demonstrates local privilege escalation and arbitrary code execution on vulnerable Android devices.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.