CVE-2024-34740 is a high-severity Android Framework elevation-of-privilege vulnerability in the attributeBytesBase64 and attributeBytesHex methods of BinaryXmlSerializer.java. An integer-overflow condition can permit arbitrary XML injection during binary XML serialization, enabling a local attacker to affect XML content processed in a privileged context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a comprehensive proof-of-concept (PoC) exploit for CVE-2024-34740, a vulnerability in Android's handling of binary XML (ABX) files used by system_server to store persistent state. The exploit is implemented as an Android application (AbxOverflow) and a secondary APK (droppedapk) that is installed with system privileges. The main exploit logic is in Java, with supporting shell scripts for file manipulation and session management. The exploit works in multiple stages: 1. It crafts a malicious binary XML payload to exploit an integer overflow in BinaryXmlSerializer.attributeBytesBase64(), corrupting /data/system/install_sessions.xml. 2. It then patches /data/system/packages.xml to register a new APK (droppedapk) as trusted for the privileged sharedUserId android.uid.system, even if the signature does not match. 3. The system_server process is crashed and restarted to force it to reload the modified state files. 4. Upon reboot, the dropped APK is launched with system_server privileges, allowing arbitrary code execution in this highly privileged context. The repository includes: - Full Android app source code for the exploit and the dropped APK. - Scripts for moving APKs, peeking and wiping install sessions. - Example XML files for reference. - A detailed README explaining the vulnerability, exploitation steps, and references to upstream patches and advisories. Key fingerprintable endpoints include the system state files /data/system/install_sessions.xml and /data/system/packages.xml, as well as the dropped APK's installation directory. The exploit is local and requires significant privileges (root or userdebug/eng build) to execute, but demonstrates a critical flaw in Android's package management system prior to the August 2024 patch.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.