CVE-2013-4787Active Exploitation(google / android)

LOWCVSS 9.3 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for google android systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrary code via an application package file (APK) that is modified in a way that does not violate the cryptographic signature, probably involving multiple entries in a Zip file with the same name in which one entry is validated but the other entry is installed, aka Android security bug 8219321 and the "Master Key" vulnerability.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-310

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
android

31 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-11: 2Active Exploitation · 2026-08-11: 108-11
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets4 URLs
Full discourse2 posts
  • userlolxxl@userlolxxl
    Active Exploitation

    @UCPGoA23 @medsci_yb3r @TELUS @TELUSsupport @Google @GooglePixel_US @Norton @LifeLock @GenDigitalInc @YourAlberta @CrimeStoppersAB @RCMPAlberta @ADanielHill @rcmpgrcpolice @virustotal @UAlberta @NANOantivirus @LevelBlueCyber @HybridAnalysis @KulinskiArkadi OTX pulse 6a7aa707929c9377594dd171 👉Telus & Norton Google Pixel 7a - 08.10.26 https://www.virustotal.com/gui/file/d9b0d1d8ad38025c315af041f2019425025868e65e88493f4a9fb745d8418863/detection exploited CVE-2013-4787 "Characterizing Android app signing issues" https://par.nsf.gov/servlets/purl/10174071 & contacts https://www.virustotal.com/gui/domain/assets.adobedtm.com/community contacted by rootkits e.g. https://www.virustotal.com/graph/embed/g77a0b8c9142946eea693e76620e837ed14ff93b73de74881b1610d39ff5d9e41?theme=dark https://t.co/WeRFgn5QwJ

    Post summary

    The tweet reports that CVE‑2013‑4787 is actively being exploited, citing a VirusTotal detection file but providing no patch, PoC, or detailed vulnerability information.

    08080222
    112 followersView on X
  • userlolxxl@userlolxxl
    General

    @medsci_yb3r @UCPGoA23 @TELUS @TELUSsupport @Google @GooglePixel_US @Norton @LifeLock @GenDigitalInc @YourAlberta @CrimeStoppersAB @RCMPAlberta @ADanielHill @rcmpgrcpolice @virustotal @UAlberta @NANOantivirus @LevelBlueCyber @HybridAnalysis @KulinskiArkadi also my question ... I intentionally used the past tense: Telus & Norton Google Pixel 7a - 08.10.26 https://www.virustotal.com/gui/file/d9b0d1d8ad38025c315af041f2019425025868e65e88493f4a9fb745d8418863/detection EXPLOITED CVE-2013-4787 "Characterizing Android app signing issues" https://par.nsf.gov/servlets/purl/10174071 - reading the article, this vulnerability was disclosed⁉️2013

    Post summary

    The tweet references CVE‑2013‑4787 and a VirusTotal detection but lacks proof‑of‑concept, exploit code, patch, or technical detail, providing only a claim of exploitation.

    11030106
    112 followersView on X
CPE platform detail33 entries

33 of 33 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid1.6--
OSgoogleandroid2.0--
OSgoogleandroid2.0.1--
OSgoogleandroid2.1--
OSgoogleandroid2.2--
OSgoogleandroid2.2--
OSgoogleandroid2.2.1--
OSgoogleandroid2.2.2--
OSgoogleandroid2.2.3--
OSgoogleandroid2.3--
OSgoogleandroid2.3--
OSgoogleandroid2.3.1--
OSgoogleandroid2.3.2--
OSgoogleandroid2.3.3--
OSgoogleandroid2.3.4--
OSgoogleandroid2.3.5--
OSgoogleandroid2.3.6--
OSgoogleandroid2.3.7--
OSgoogleandroid3.0--
OSgoogleandroid3.1--
OSgoogleandroid3.2--
OSgoogleandroid3.2.1--
OSgoogleandroid3.2.2--
OSgoogleandroid3.2.4--
OSgoogleandroid3.2.6--
OSgoogleandroid4.0--
OSgoogleandroid4.0.1--
OSgoogleandroid4.0.2--
OSgoogleandroid4.0.3--
OSgoogleandroid4.0.4--
OSgoogleandroid4.1--
OSgoogleandroid4.1.2--
OSgoogleandroid4.2--

Explore more