CVE detail
CVE-2019-2215
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
20 source links · newest first
- Pwning the all Google phone with a non-Google bugGitHub Security Lab
It turns out that the first “all Google” phone includes a non-Google bug. Learn about the details of CVE-2022-38181, a vulnerability in the Arm Mali GPU. Join me on my journey through reporting the vulnerability to the Android security team, and the exploit that used this vulnerability to gain arbitrary kernel code execution and root on a Pixel 6 from an Android app.
vendorgithub.blogJan 23, 2023, 3:05 PM - Rooting malware discovered on Google Play, Samsung Galaxy StoreHelp Net Security
Researchers have discovered 19 mobile apps carrying rooting malware on official and third-party Android app stores, including Google Play and Samsung Galaxy Store. “While rare, rooting malware is very dangerous,” Lookout researchers Kristina Balaam and Paul Shunk explained. “By using the rooting process to gain privileged access to the Android operating system, the threat actor can silently grant themselves dangerous permissions or install additional malware — steps that would normally require user interaction. Elevated privileges … More →
newswww.helpnetsecurity.comNov 3, 2021, 6:45 AM The Google Play store has become better in recent years at policing malware, raising the bar for attackers, but well-crafted stealthy Trojans continue to slip in from time to time. Such is the case of AbstractEmu, a recently discovered threat masquerading as utility apps and capable of gaining full control over devices through root exploits. […]
newswww.csoonline.comNov 2, 2021, 3:37 PM- AbstractEmu, a new Android malware with rooting capabilitiesSecurity Affairs
AbstractEmu is a new Android malware that can root infected devices to take complete control and evade detection with different tricks. Security researchers at the Lookout Threat Labs have discovered a new Android malware, dubbed AbstractEmu, with rooting capabilities that is distributed on Google Play and prominent third-party stores (i.e. Amazon Appstore and the Samsung Galaxy Store). The malware […]
newssecurityaffairs.comOct 28, 2021, 3:47 PM The number of identified zero-day vulnerabilities being exploited has increased in 2019, revealing a broadened access to these security flaws, according to security firm FireEye.
newswww.securityweek.comApr 7, 2020, 8:15 PM- 13th January – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 13th January 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Austria’s foreign ministry has suffered a serious cyber-attack, allegedly conducted by a foreign state. US government-funded low-cost UMX mobile phones include preinstalled “unremovable” malware. The malware, a variant of HiddenAds, is […]
vendorresearch.checkpoint.comJan 13, 2020, 12:45 PM Here’s an overview of some of last week’s most interesting news and articles: Travelex extorted by ransomware gang, services still offline a week after the hit On the last day of 2019, foreign exchange company Travelex was hit by cyber attackers wielding the Sodinokibi (aka REvil) ransomware. More than a week later, the company’s websites and online services are still offline despite the company’s remediation efforts. January 2020 Patch Tuesday forecast: Let’s start the new … More →
newswww.helpnetsecurity.comJan 12, 2020, 2:50 PM- App on Google Play exploited Android bug to deliver spywareHelp Net Security
Google has pulled three malicious apps from Google Play, one of which exploits a recently patched kernel privilege escalation bug in Android (CVE-2019-2215) to install the app aimed at spying on users. About CVE-2019-2215 The existence of CVE-2019-2215 was discovered in late 2019 when it was spotted being exploited in the wild. Researchers with Google’s Threat Analysis Group and other external parties believe that the exploit originated with NSO Group, an Israel-based company that specializes … More →
newswww.helpnetsecurity.comJan 8, 2020, 2:19 PM - Malicious app exploiting CVE-2019-2215 zero-day available in Google Play since MarchSecurity Affairs
Security experts have found a malicious app in the Google Play that exploits the recently patched CVE-2019-2215 zero-day vulnerability. Earlier October, Google Project Zero researchers Maddie Stone publicly disclosed a zero-day vulnerability, tracked as CVE-2019-2215, in Android. Maddie Stone published technical details and a proof-of-concept exploit for the high-severity security vulnerability, seven days after she reported it to the colleagues […]
newssecurityaffairs.comJan 7, 2020, 9:19 AM A malicious application in the Google Play store targeted a recently patched zero-day vulnerability that affects multiple Android devices, including Google’s Pixel phones.
newswww.securityweek.comJan 7, 2020, 5:29 AM- Week in review: Insider threat essentials, tracing IP hijackers, cryptojacking worm hits Docker hostsHelp Net Security
Here’s an overview of some of last week’s most interesting news, reviews and articles: “Smart city” governments should also be smart about security While the definition of “smart city” is still under debate, one thing is indisputable: the technologies used to make smart cities a reality are currently acquired and deployed after very little (or even no) security testing. Cryptojacking worm compromised over 2,000 Docker hosts Security researchers have discovered a cryptojacking worm that propagates … More →
newswww.helpnetsecurity.comOct 20, 2019, 3:55 PM - Security Affairs newsletter Round 236Security Affairs
A new round of the weekly newsletter arrived! The best news of the week with Security Affairs Hi folk, let me inform you that I suspended the newsletter service, anyway I’ll continue to provide you a list of published posts every week through the blog. A new Mac malware dubbed Tarmac has been distributed via […]
newssecurityaffairs.comOct 20, 2019, 12:25 PM A researcher has published a proof-of-concept (PoC) exploit code for the CVE-2019-2215 zero-day flaw in Android recently addressed by Google Earlier October, Google Project Zero researchers Maddie Stone publicly disclosed a zero-day vulnerability, tracked as CVE-2019-2215, in Android. According to the expert, the bug was allegedly being used or sold by the controversial surveillance firm NSO […]
newssecurityaffairs.comOct 18, 2019, 8:56 AMA security researcher has published a proof-of-concept (PoC) exploit for the recently addressed Android zero-day vulnerability that impacts Pixel 2 devices.
newswww.securityweek.comOct 18, 2019, 7:04 AMLate last month Google Project Zero researcher Maddie Stone detailed a zero-day Android privilege escalation vulnerability (CVE-2019-2215) and revealed that it is actively being exploited in attacks in the wild. She also provided PoC code that could help researchers check which Android-based devices are vulnerable and which are not. One of those has decided to go further. Achieving “root” through a malicious app “The base PoC left us with a full kernel read/write primitive, essentially … More →
newswww.helpnetsecurity.comOct 17, 2019, 1:19 PMGoogle’s October 2019 set of security patches for Android address a total of 26 vulnerabilities in the operating system, including a couple of remote code execution bugs impacting Android 10.
newswww.securityweek.comOct 8, 2019, 2:03 PM- 7th October – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 2nd October 2019, please download our Threat Intelligence Bulletin TOp attacks AND breacheS Check Point Research has uncovered new information on an espionage campaign suspected to be conducted by the Egyptian government. The targets of the campaign are journalists, politicians, human rights activists and […]
vendorresearch.checkpoint.comOct 7, 2019, 1:04 PM Fully patched Pixel 2 devices, even those running Android 10 preview, are impacted by a vulnerability that has already been abused in attacks, a Google Project Zero security researcher has discovered.
newswww.securityweek.comOct 4, 2019, 12:41 PM- Project Zero researcher found unpatched Android zero-day likely exploited by NSO groupSecurity Affairs
Google Project Zero researcher Maddie Stone discovered a critical unpatched zero-day vulnerability affecting the Android mobile operating system. Maddie Stone, a member of the Google elite team Project Zero, discovered a critical unpatched zero-day vulnerability affecting the Android mobile operating system. According to the expert, the bug, tracked as CVE-2019-2215, was allegedly being used or […]
newssecurityaffairs.comOct 4, 2019, 11:48 AM - Unpatched Android flaw exploited by attackers, impacts Pixel, Samsung, Xiaomi devicesHelp Net Security
A privilege escalation vulnerability affecting phones running Android 8.x and later is being leveraged by attackers in the wild, Google has revealed. Interestingly enough, the flaw was patched in late 2017 in v4.14 of the Linux kernel and in Android versions 3.18, 4.4, and 4.9, but the fix was apparently never propagated to later Android versions. Who’s affected? Maddie Stone, a Senior Security Engineer on the Android Security team at Google, revealed that a number … More →
newswww.helpnetsecurity.comOct 4, 2019, 10:17 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2020-8835CVSS 7.8 · High
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads a…
- CVE-2019-14814CVSS 7.8 · High
There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial…
- CVE-2024-26641CVSS 5.5 · Medium
In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access uniti…
- CVE-2020-9383CVSS 7.1 · High
An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked…
- CVE-2019-19448CVSS 7.8 · High
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in…
- CVE-2019-18683CVSS 7.0 · High
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users…