CVE-2026-28576 is an SQL injection vulnerability in Android Contacts Provider. Insufficiently constrained SQL input can enable unauthorized access to the contacts database, resulting in local information disclosure.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This 83-file repository contains extensive Markdown research material plus two Android applications: a newer Kotlin "Red Team Tool" under dashboard/new_redteam_app and a legacy Java PoC under poc_app_old/poc_app. Neither is part of a recognized exploit framework. The active Kotlin app uses a consent screen, invokes ACTION_PICK on the Android contacts provider, saves the returned URI grant, and passes SQL-subquery predicates as ContentResolver.query() selections. Its ExploitEngine uses cursor row presence as a boolean oracle to enumerate ContactsProvider mimetype IDs, row counts, raw contact IDs, and data1 values across 11 contact mimetypes. The newer variant adds a configurable HTTP JSON uploader, optional Firebase Realtime Database writes, a results viewer/exporter, and a BOOT_COMPLETED receiver intended to restart background collection when a saved grant remains valid. The old Java app is a reference implementation with comparable extraction logic but no implemented C2 uploader. Operational limitations are material: the Kotlin code assigns to an immutable rawContactId property and invokes suspend withContext/runExploit from a non-suspend start method, indicating compilation defects as shown. It also lacks INTERNET, RECEIVE_BOOT_COMPLETED, and foreground-service-related permissions in its manifest; consequently HTTP/Firebase transmission and boot persistence are not viable as currently declared. The documents also contain conflicting publication/completion dates, so CVE and version claims should be independently verified. Despite those defects, the repository contains substantive exploit logic rather than only detection code or documentation.
This is a standalone Android proof-of-concept repository for CVE-2026-28576, not a framework module. Its functional exploit is `poc/src/com/poc/cve202628576/MainActivity.java`, a Java Android activity that launches the system contact picker, retains the resulting read-only URI grant for one selected contact, and issues injected selection clauses through `ContentResolver.query()`. On vulnerable Android 17 builds, the Contacts Provider's strict SQL parsing is disabled for apps targeting SDK 36 or lower due to compat change 484953293. The activity uses response row count as a blind boolean oracle to enumerate and recover names, phones, and emails from ungranted contact rows. The manifest intentionally declares no permissions, notably no READ_CONTACTS. `poc/build.sh` builds and debug-signs the APK without Gradle with target SDK 36. README and REPRODUCE documentation explain emulator setup, test contact insertion, picker-based execution, and a patched control test; evidence logs demonstrate successful extraction and rejection once strict SQL checks are enabled. The repository has no command shell, persistence, privilege-escalation, or remote C2/exfiltration component.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.