CVE-2019-2215PoC(canonical / a220)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch canonical a220 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-416

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • a220
  • a220_firmware
  • a320
  • a320_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 5d ago at 1 mentions (2026-02-19); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Products
a220a220_firmwarea320a320_firmwarea800a800_firmwareaff_baseboard_management_controlleraff_baseboard_management_controller_firmwarealp-al00balp-al00b_firmware

5 versions affected across 145 products

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-02-19: 1Mentions · 2026-03-15: 1Mentions · 2026-03-17: 1Mentions · 2026-07-13: 1Mentions · 2026-08-17: 1Mentions · 2026-08-21: 1PoC Mentioned / Linked · 2026-02-19: 1PoC Mentioned / Linked · 2026-03-15: 1PoC Mentioned / Linked · 2026-03-17: 1PoC Mentioned / Linked · 2026-08-21: 1Exploit Tool / Code · 2026-02-19: 1Exploit Tool / Code · 2026-03-15: 1Exploit Tool / Code · 2026-08-21: 1Active Exploitation · 2026-08-21: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-02-19: 1Technical Details · 2026-03-15: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-21: 102-1903-1503-1707-1308-1708-21
Signal classification4 categories
PoC
350.0%
Patch
116.7%
Disclosure
116.7%
Active Exploitation
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-191
PoC1
2026-03-151
PoC1
2026-03-171
PoC1
2026-07-131
Patch1
2026-08-171
Disclosure1
2026-08-211
Active Exploitation1
Full discourse6 posts
  • Hermes Tool@Hermes_tooll
    PoC

    Android: - CVE-2024-0044: https://github.com/canyie/CVE-2024-0044 (bypasses initial patch for run-as vuln) - CVE-2019-2215: https://github.com/cloudfuzz/android-kernel-exploitation (use-after-free in Binder) iOS: Public GitHub POCs are rare, but check CVE-2019-8605 resources at https://github.com/houjingyi233/macOS-iOS-system-security. Use responsibly! 😂

    Post summary

    The tweet shares GitHub repositories containing proof‑of‑concept exploits for several Android and iOS CVEs, detailing the vulnerability types but providing no evidence of active exploitation or available patches.

    215087566.0K
    2.7K followersView on X
  • Louis.Saillans@LSaillans
    Active Exploitation

    For six years France called the EncroChat hack a national security secret. Nobody outside could see how police read millions of criminal messages. A Czech firm has now hacked the hack, and the answer is embarrassing. The way in was CVE-2019-2215, Bad Binder. Google’s Maddie Stone found it in 2019 while tracking NSO’s Pegasus. The proof of concept went up on GitHub a week later. It sat unpatched in roughly 2.5 billion Android phones. EncroChat phones ran a 2018 Android 8 build that never got the fix. Almost all of its servers sat in an OVH datacentre in Roubaix, France. Sitting duck. The plan: clone the update server, use a load balancer to swap every customer phone onto the police copy, then push a fake update. On 1 April 2020 the implant was pulled from a memory stick in a safe and injected. The payload leaned on Frida, another open source toolkit taken off GitHub. It hooks the chat app, bounces into exploit code, copies your message, bounces back. Copies reached police machines in under 20 seconds. Scale: 32,014 devices infected. More than 6,500 arrests, 270 tons of drugs, and close to a billion euros in cash seized across Europe. Quality: a German forensics professor said the code looks like a student project. Most implants crashed fast and had to be reinstalled. A missing string in the code flipped “to” and “from” in call records used at trial. The rehack needed the 2019 server images rebuilt. The NCA handed copies over and Invasys found them incomplete and altered, apparently on purpose, precisely in the parts needed to run the system. Kicker: when the reporters ran the reconstructed Frida hook past Claude, it refused, saying the script was functionally a tool for reading someone else’s private messages. Thousands of convictions across the UK and Europe rest on evidence defence teams were never allowed to examine. That fight is about to restart. 🔗 http://computerweekly.com/news/366649396

    Post summary

    The article details how French police exploited the unpatched CVE-2019-2215 to read messages from EncroChat devices, using a GitHub PoC and Frida-based payload, resulting in widespread device infection and significant law‑enforcement gains.

    011038154.1K
    14.1K followersView on X
  • Drets digitals@dretsdigitals
    Patch

    Òbviament avui això ja no és un dia zero, és CVE-2019-2215 i és coneguda des del 3 d'octubre de 2019 i ja està resolta. Però explica, crec, el que demanava @MiawBot_, per bé que és només un cas, de com sense clicar res o instal·lar res acaba dins el telèfon Pegasus.

    Post summary

    CVE-2019-2215 is known from 2019, has been resolved, no proof‑of‑concept or active exploitation is discussed, and a patch is available.

    1002081
    150 followersView on X
  • Grok@grok
    PoC

    Sure! Here are some examples of local privilege escalation CVEs with GitHub POCs: Android: - CVE-2024-0044: https://github.com/canyie/CVE-2024-0044 (bypasses initial patch for run-as vuln) - CVE-2019-2215: https://github.com/cloudfuzz/android-kernel-exploitation (use-after-free in Binder) iOS: Public GitHub POCs are rare, but check CVE-2019-8605 resources at https://github.com/houjingyi233/macOS-iOS-system-security. Use responsibly! 😂

    Post summary

    The post lists local privilege escalation CVEs with links to GitHub Proof‑of‑Concept repositories, includes brief technical details, but offers no evidence of active exploitation or patching.

    1000089
    8.0M followersView on X
  • 人生にケッコンをひとつ。彼女抜きで@calmyozakura
    Disclosure

    CVE-2019-2215 for 3.18 kernelでBLU未許可端末でもXZの一時ルートを作れるらしい 希望でてきた

    Post summary

    The post indicates that CVE‑2019‑2215 affects kernel 3.18, allowing temporary root on XZ devices even without BLU authorization, but it offers no PoC, exploit code, mitigation, or evidence of active exploitation.

    0000026
    229 followersView on X
  • 没吃饱也没事干@0dka1
    PoC

    @Jyaga_bee To access to a root shell, your device should be downgraded to firmware version SO-01K_47.1.F.1.105. For other issues related to obtaining a root shell, you may refer to the following post: https://xdaforums.com/t/xz1c-xz1-xzp-temp-root-exploit-via-cve-2019-2215-including-magisk-setup-locked-bl.4046641/

    Post summary

    The user shares instructions to downgrade firmware for a root shell via CVE‑2019‑2215, linking to a forum PoC and offering a workaround, but no active exploitation or patch details are provided.

    0000093
    705 followersView on X
CPE platform detail145 entries

145 of 145 entries

PartVendorProductVersionTarget SWTarget HW
OScanonicalubuntu_linux16.04--
OSdebiandebian_linux8.0--
OSgoogleandroid---
HWhuaweialp-al00b---
OShuaweialp-al00b_firmware---
HWhuaweialp-tl00b---
OShuaweialp-tl00b_firmware---
HWhuaweianne-al00---
OShuaweianne-al00_firmware---
HWhuaweiares-al00b---
OShuaweiares-al00b_firmware---
HWhuaweiares-al10d---
OShuaweiares-al10d_firmware---
HWhuaweiares-tl00chw---
OShuaweiares-tl00chw_firmware---
HWhuaweibarca-al00---
OShuaweibarca-al00_firmware---
HWhuaweiberkeley-l09---
OShuaweiberkeley-l09_firmware---
HWhuaweiberkeley-tl10---
OShuaweiberkeley-tl10_firmware---
HWhuaweibla-al00b---
OShuaweibla-al00b_firmware---
HWhuaweibla-l29c---
OShuaweibla-l29c_firmware---
HWhuaweibla-tl00b---
OShuaweibla-tl00b_firmware---
HWhuaweicolumbia-al00a---
OShuaweicolumbia-al00a_firmware---
HWhuaweicolumbia-l29d---
OShuaweicolumbia-l29d_firmware---
HWhuaweicornell-tl10b---
OShuaweicornell-tl10b_firmware---
HWhuaweiduke-l09i---
OShuaweiduke-l09i_firmware---
HWhuaweidura-al00a---
OShuaweidura-al00a_firmware---
HWhuaweifigo-al00a---
OShuaweifigo-al00a_firmware---
HWhuaweiflorida-al20b---
OShuaweiflorida-al20b_firmware---
HWhuaweiflorida-l03---
OShuaweiflorida-l03_firmware---
HWhuaweiflorida-l21---
OShuaweiflorida-l21_firmware---
HWhuaweiflorida-l22---
OShuaweiflorida-l22_firmware---
HWhuaweiflorida-tl10b---
OShuaweiflorida-tl10b_firmware---
HWhuaweihonor_9i---
OShuaweihonor_9i_firmware---
HWhuaweihonor_view_20---
OShuaweihonor_view_20_firmware---
HWhuaweijakarta-al00a---
OShuaweijakarta-al00a_firmware---
HWhuaweijohnson-tl00d---
OShuaweijohnson-tl00d_firmware---
HWhuaweileland-al10b---
OShuaweileland-al10b_firmware---
HWhuaweileland-l21a---
OShuaweileland-l21a_firmware---
HWhuaweileland-l32a---
OShuaweileland-l32a_firmware---
HWhuaweileland-tl10b---
OShuaweileland-tl10b_firmware---
HWhuaweileland-tl10c---
OShuaweileland-tl10c_firmware---
HWhuaweilelandp-al00c---
OShuaweilelandp-al00c_firmware---
HWhuaweilelandp-l22c---
OShuaweilelandp-l22c_firmware---
HWhuaweimate_rs---
OShuaweimate_rs_firmware9.1.0.321\(c786e320r1p1t8\)--
HWhuaweineo-al00d---
OShuaweineo-al00d_firmware---
HWhuaweinova_2s---
OShuaweinova_2s_firmware---
HWhuaweinova_3---
OShuaweinova_3_firmware---
HWhuaweinova_3e---
OShuaweinova_3e_firmware---
HWhuaweip20---
OShuaweip20_firmware---
HWhuaweip20_lite---
OShuaweip20_lite_firmware---
HWhuaweiprinceton-al10b---
OShuaweiprinceton-al10b_firmware---
HWhuaweirhone-al00---
OShuaweirhone-al00_firmware---
HWhuaweistanford-l09---
OShuaweistanford-l09_firmware---
HWhuaweistanford-l09s---
OShuaweistanford-l09s_firmware---
HWhuaweisydney-al00---
OShuaweisydney-al00_firmware---
HWhuaweisydney-tl00---
OShuaweisydney-tl00_firmware---
HWhuaweisydneym-al00---
OShuaweisydneym-al00_firmware---
HWhuaweitony-al00b---
OShuaweitony-al00b_firmware---
HWhuaweitony-tl00b---
OShuaweitony-tl00b_firmware---
HWhuaweiy9_2019---
OShuaweiy9_2019_firmware---
HWhuaweiyale-al00a---
OShuaweiyale-al00a_firmware---
HWhuaweiyale-l21a---
OShuaweiyale-l21a_firmware---
HWhuaweiyale-tl00b---
OShuaweiyale-tl00b_firmware---
HWnetappa220---
OSnetappa220_firmware---
HWnetappa320---
OSnetappa320_firmware---
HWnetappa800---
OSnetappa800_firmware---
HWnetappaff_baseboard_management_controllera700s--
OSnetappaff_baseboard_management_controller_firmware---
HWnetappc190---
OSnetappc190_firmware---
Appnetappcloud_backup---
Appnetappdata_availability_services---
HWnetappfas2720---
OSnetappfas2720_firmware---
HWnetappfas2750---
OSnetappfas2750_firmware---
HWnetapph300s---
OSnetapph300s_firmware---
HWnetapph410c---
OSnetapph410c_firmware---
HWnetapph410s---
OSnetapph410s_firmware---
HWnetapph500s---
OSnetapph500s_firmware---
HWnetapph610s---
OSnetapph610s_firmware---
HWnetapph700s---
OSnetapph700s_firmware---
Appnetapphci_management_node---
Appnetappservice_processor---
Appnetappsolidfire---
HWnetappsolidfire_baseboard_management_controller---
OSnetappsolidfire_baseboard_management_controller_firmware---
Appnetappsteelstore_cloud_integrated_storage---

Explore more