logo

Exploit released for Android local elevation flaw impacting 7 OEMs

ID: 37159089-ac61-5752-9668-97feaebabd18

STIX ID: report--37159089-ac61-5752-9668-97feaebabd18

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2024-01-31

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A proof-of-concept exploit for CVE-2023-45779 — an Android local privilege escalation caused by insecure APEX module signing with public test keys — was published; the flaw affects devices from multiple OEMs, was discovered by Meta's Red Team X, and is mitigated by Android security updates dated 2023-12-05, while practical exploitation generally requires local access (adb) though the PoC raises risk if chained with other compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.