CVE-2017-13236
HIGHAndroid 8.0-8.1 - Incorrect Permission Assignment for Critical Resource in KeyStore Service
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-13236. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a race condition in the Android Keystore service's PID-based SELinux context enforcement to generate a device-unique key without proper privileges. The attack involves forking a process, killing it, and spawning a new 'priv_app' instance to bypass access controls.
Description
In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-68217699.
Exploits (1)
This exploit leverages a race condition in the Android Keystore service's PID-based SELinux context enforcement to generate a device-unique key without proper privileges. The attack involves forking a process, killing it, and spawning a new 'priv_app' instance to bypass access controls.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H