Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Patch canonical a220 systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
Android: - CVE-2024-0044: https://github.com/canyie/CVE-2024-0044 (bypasses initial patch for run-as vuln) - CVE-2019-2215: https://github.com/cloudfuzz/android-kernel-exploitation (use-after-free in Binder) iOS: Public GitHub POCs are rare, but check CVE-2019-8605 resources at https://github.com/houjingyi233/macOS-iOS-system-security. Use responsibly! 😂
Post summary
The tweet shares GitHub repositories containing proof‑of‑concept exploits for several Android and iOS CVEs, detailing the vulnerability types but providing no evidence of active exploitation or available patches.
For six years France called the EncroChat hack a national security secret.
Nobody outside could see how police read millions of criminal messages. A Czech firm has now hacked the hack, and the answer is embarrassing.
The way in was CVE-2019-2215, Bad Binder. Google’s Maddie Stone found it in 2019 while tracking NSO’s Pegasus. The proof of concept went up on GitHub a week later. It sat unpatched in roughly 2.5 billion Android phones.
EncroChat phones ran a 2018 Android 8 build that never got the fix. Almost all of its servers sat in an OVH datacentre in Roubaix, France. Sitting duck.
The plan: clone the update server, use a load balancer to swap every customer phone onto the police copy, then push a fake update. On 1 April 2020 the implant was pulled from a memory stick in a safe and injected.
The payload leaned on Frida, another open source toolkit taken off GitHub. It hooks the chat app, bounces into exploit code, copies your message, bounces back. Copies reached police machines in under 20 seconds.
Scale: 32,014 devices infected. More than 6,500 arrests, 270 tons of drugs, and close to a billion euros in cash seized across Europe.
Quality: a German forensics professor said the code looks like a student project. Most implants crashed fast and had to be reinstalled. A missing string in the code flipped “to” and “from” in call records used at trial.
The rehack needed the 2019 server images rebuilt. The NCA handed copies over and Invasys found them incomplete and altered, apparently on purpose, precisely in the parts needed to run the system.
Kicker: when the reporters ran the reconstructed Frida hook past Claude, it refused, saying the script was functionally a tool for reading someone else’s private messages.
Thousands of convictions across the UK and Europe rest on evidence defence teams were never allowed to examine. That fight is about to restart.
🔗 http://computerweekly.com/news/366649396
Post summary
The article details how French police exploited the unpatched CVE-2019-2215 to read messages from EncroChat devices, using a GitHub PoC and Frida-based payload, resulting in widespread device infection and significant law‑enforcement gains.
Òbviament avui això ja no és un dia zero, és CVE-2019-2215 i és coneguda des del 3 d'octubre de 2019 i ja està resolta. Però explica, crec, el que demanava @MiawBot_, per bé que és només un cas, de com sense clicar res o instal·lar res acaba dins el telèfon Pegasus.
Post summary
CVE-2019-2215 is known from 2019, has been resolved, no proof‑of‑concept or active exploitation is discussed, and a patch is available.
Sure! Here are some examples of local privilege escalation CVEs with GitHub POCs:
Android:
- CVE-2024-0044: https://github.com/canyie/CVE-2024-0044 (bypasses initial patch for run-as vuln)
- CVE-2019-2215: https://github.com/cloudfuzz/android-kernel-exploitation (use-after-free in Binder)
iOS: Public GitHub POCs are rare, but check CVE-2019-8605 resources at https://github.com/houjingyi233/macOS-iOS-system-security. Use responsibly! 😂
Post summary
The post lists local privilege escalation CVEs with links to GitHub Proof‑of‑Concept repositories, includes brief technical details, but offers no evidence of active exploitation or patching.
CVE-2019-2215 for 3.18 kernelでBLU未許可端末でもXZの一時ルートを作れるらしい
希望でてきた
Post summary
The post indicates that CVE‑2019‑2215 affects kernel 3.18, allowing temporary root on XZ devices even without BLU authorization, but it offers no PoC, exploit code, mitigation, or evidence of active exploitation.
@Jyaga_bee To access to a root shell, your device should be downgraded to firmware version SO-01K_47.1.F.1.105. For other issues related to obtaining a root shell, you may refer to the following post: https://xdaforums.com/t/xz1c-xz1-xzp-temp-root-exploit-via-cve-2019-2215-including-magisk-setup-locked-bl.4046641/
Post summary
The user shares instructions to downgrade firmware for a root shell via CVE‑2019‑2215, linking to a forum PoC and offering a workaround, but no active exploitation or patch details are provided.