Android Backup Agent Arbitrary Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 20 Apr 2015.

  1. Packet Storm

    Packet Storm Guest

    The Android backup agent implementation was vulnerable to privilege escalation and race condition. An attacker with adb shell access could run arbitrary code as the system (1000) user (or any other valid package). The attack is tested on Android OS 4.4.4.

    Continue reading...
     

Share This Page

Loading...