🔧 Programmierung[$] Stabilizing Rust's never type(08.09.2026 um 15:34 Uhr)
🕵️ SicherheitslückenForgejo 16.0.4 and 15.0.8 address critical security vulnerability(10.09.2026 um 22:05 Uhr)
🔧 AI Nachrichten Canonical joins the Open Secure AI Alliance(03.09.2026 um 03:02 Uhr)
🔧 AI Nachrichten Alberta Tech: I built an app to get my boss to listen to me(27.08.2026 um 16:41 Uhr)
🔧 Programmierung[$] Stabilizing Rust's never type(08.09.2026 um 15:34 Uhr)
🕵️ SicherheitslückenForgejo 16.0.4 and 15.0.8 address critical security vulnerability(10.09.2026 um 22:05 Uhr)
🔧 AI Nachrichten Canonical joins the Open Secure AI Alliance(03.09.2026 um 03:02 Uhr)
🔧 AI Nachrichten Alberta Tech: I built an app to get my boss to listen to me(27.08.2026 um 16:41 Uhr)

🕵️ Sicherheitslücken 🕛 vor 1 Tag 2 Min Lesezeit
0

USENIX: WOOT '26 - Exploiting Android Apps with Counterfeit Art

↗ Quelle (YouTube · USENIX)
🗣️ Stimme:
📺
YouTube · USENIX
155 YouTube-Aufrufe
Exploiting Android Apps with Counterfeit Art

Rokhaya-Diamil Fall and Philipp Mao, EPFL; Martin Wagner, Asymmetric Research; Mathias Payer, EPFL

Arbitrary file overwrite vulnerabilities are common in Android apps. However, the security impact of such vulnerabilities has so far been highly app-dependent. We present a new, app-agnostic, persistent technique that turns arbitrary file overwrites into code execution by targeting the runtime-generated app image file. This file is used by the Android Runtime to cache a snapshot of the app’s classes and is writable within an app’s sandbox. By replacing this file with a malicious image, attackers gain code execution when the app restarts.
We describe two exploitation strategies: a local attack that, assuming an ASLR leak, leverages an arbitrary memory write during image decompression to corrupt Android Runtime objects and hijack control flow. More importantly, we demonstrate a remote attack that requires no ASLR leak and instead abuses image relocation logic to inject and execute attacker-controlled Dalvik bytecode.
We demonstrate the practicality of both techniques by exploiting real n-day or 0-day arbitrary file overwrite vulnerabilities on commercial phones. We showcase the local technique with a zero-click privilege escalation chain from an untrusted app to the system user, exploiting an arbitrary file overwrite in the OnePlus backup app. We present the remote technique by exploiting the same file overwrite vulnerability over the network. To further demonstrate the remote technique, we present a new variant of the Pwn2Own24 Galaxy S24 chain, which leveraging our remote technique, now achieves code execution in the privileged platform_app context. We reveal the security impact of arbitrary file overwrite vulnerabilities in Android apps and present memory corruption exploitation in the Android Runtime.

View the full WOOT '26 program at https://www.usenix.org/conference/woot26/technical-sessions
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Sony FE 8-14 mm F3.5: Fisheye mit Zirkular-Diagonal-Zoom im Test
1 Quelle
KI-Modell für den Mond: Open-Source-Projekt soll Wasser-Eis finden
1 Quelle
Kirby and the World Beyond: Neues 3D-Abenteuer startet Anfang 2027