CVE-2020-0022 an Android 8.0-9.0 Bluetooth Zero-Click RCE – BlueFrag – Insinuator.net
April 24, 2020
8:39 p.m.
https://insinuator.net/2020/04/cve-2020-0022-an-android-8-0-9-0-bluetooth-ze... [...] In the following, we describe a Bluetooth zero-click short-distance RCE exploit against Android 9, which got assigned CVE-2020-0022 . We go through all steps required to establish a remote shell on a Samsung Galaxy S10e, which was working on an up-to-date Android 9 when reporting the issue on November 3 2019. The initial flaw used for this exploit is still present in Android 10, but we utilize an additional bug in Bionic (Android’s libc implementation), which makes exploitation way easier. The bug was finally fixed in the security patch from 1.2.2020 in A-143894715. Here is a demo of the full proof of concept: [...]
2164
Age (days ago)
2164
Last active (days ago)
0 comments
1 participants
participants (1)
-
Alberto Cammozzo