
CISA report on vulnerabilities: Improper crypto signature check (CVE-2022-1739): Lets fake apps install. • Mutable self-attestation (CVE-2022-1740): Hides malware in logs or hashes. • Hidden terminal emulator (CVE-2022-1741): Backdoor for root access. • Safe mode reboot trick (CVE-2022-1742): Drops into Android OS for full control. • Path traversal in files (CVE-2022-1743): Zip tricks execute code from election defs. • Unnecessary privileges (CVE-2022-1744): Apps run too high, easy escalation. • Technician card spoofing (CVE-2022-1745): Fake cards get admin rights. • Poll worker auth leak (CVE-2022-1746): Exposes keys for other machines. • Voter session forgery (CVE-2022-1747): Print unlimited ballots.
Post summary
The CISA report lists several CVEs, describing their potential impact, but offers no PoC, exploit details, patches, or evidence of active exploitation.
