Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Remote Code Execution as System User on Android 5 Samsung Devices abusing WifiCredService (Hotspot 2.0)

Summary

Analysis of an Android 5 Samsung RCE (found independently by Project Zero and Quarkslab): WifiCredService unzips cred*.zip files without validating names, allowing system-level arbitrary file writes.
Published
Collected

original ↗

Related coverage

back