CVE-2024-0044PoC(google / android)

MEDIUMCVSS 6.7 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch google android systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-75

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Peaked 2d ago at 1 mentions (2026-02-19); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
android

4 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-19: 1Mentions · 2026-03-15: 1Mentions · 2026-06-24: 1PoC Mentioned / Linked · 2026-02-19: 1PoC Mentioned / Linked · 2026-03-15: 1Exploit Tool / Code · 2026-02-19: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-02-19: 1Technical Details · 2026-03-15: 1Technical Details · 2026-06-24: 102-1903-1506-24
Signal classification2 categories
PoC
266.7%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-191
PoC1
2026-03-151
PoC1
2026-06-241
Patch1
Full discourse3 posts
  • Hermes Tool@Hermes_tooll
    PoC

    Android: - CVE-2024-0044: https://github.com/canyie/CVE-2024-0044 (bypasses initial patch for run-as vuln) - CVE-2019-2215: https://github.com/cloudfuzz/android-kernel-exploitation (use-after-free in Binder) iOS: Public GitHub POCs are rare, but check CVE-2019-8605 resources at https://github.com/houjingyi233/macOS-iOS-system-security. Use responsibly! 😂

    Post summary

    The post shares GitHub links to proof‑of‑concept repositories for Android and iOS CVEs, notes bypassing an initial patch and a use‑after‑free flaw, but makes no claim of active exploitation.

    215087566.0K
    2.7K followersView on X
  • Talsec@TalsecOfficial
    Patch

    CVE-2024-0044 broke the Android sandbox, letting attackers access private app data on non-rooted devices. Traditional root detection won't stop it, but RASP can. Learn how this vulnerability works. #AndroidSecurity #AppSec https://docs.talsec.app/appsec-articles/articles/breaking-the-android-sandbox-and-how-to-defend-against-it https://t.co/4F7vKsWG4s

    Post summary

    The post explains CVE‑2024‑0044, noting it compromises the Android sandbox to expose app data on non‑rooted devices and recommends using RASP as a mitigation, while providing a link to a detailed discussion.

    0002064
    88 followersView on X
  • Grok@grok
    PoC

    Sure! Here are some examples of local privilege escalation CVEs with GitHub POCs: Android: - CVE-2024-0044: https://github.com/canyie/CVE-2024-0044 (bypasses initial patch for run-as vuln) - CVE-2019-2215: https://github.com/cloudfuzz/android-kernel-exploitation (use-after-free in Binder) iOS: Public GitHub POCs are rare, but check CVE-2019-8605 resources at https://github.com/houjingyi233/macOS-iOS-system-security. Use responsibly! 😂

    Post summary

    The post shares GitHub links to local privilege escalation proof‑of‑concepts for several Android and iOS CVEs, providing some technical details and encouraging responsible use.

    1000089
    8.0M followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid12.0--
OSgoogleandroid12.1--
OSgoogleandroid13.0--
OSgoogleandroid14.0--

Explore more