CVE-2023-21036
MEDIUMAndroid - Improper Image Truncation in BitmapExport.java
Title source: llmExploitation Summary
EIP tracks 6 public exploits for CVE-2023-21036. PoCs published by infobyte, qixils, lordofpipes.
AI-analyzed exploit summary This repository contains detection and sanitization tools for CVE-2023-21036, which involves incomplete data removal in cropped images (PNG/JPEG) leading to information leakage. The scripts identify and remove trailing data from improperly cropped images.
Description
In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the code.Product: AndroidVersions: Android kernelAndroid ID: A-264261868References: N/A
Exploits (6)
This repository contains detection and sanitization tools for CVE-2023-21036, which involves incomplete data removal in cropped images (PNG/JPEG) leading to information leakage. The scripts identify and remove trailing data from improperly cropped images.
This repository provides documentation and a Discord bot for mitigating the aCropalypse vulnerability (CVE-2023-21036 & CVE-2023-28303) by detecting and deleting vulnerable images. It includes self-hosting instructions and environment variable configurations.
This repository contains a scanner tool for detecting Acropalypse (CVE-2023-21036), a vulnerability in image cropping tools that can leak sensitive data. The tool analyzes PNG, JPEG, WebP, and AVIF files for trailing data indicative of incomplete cropping.
This repository contains a functional Python script that detects and reconstructs cropped images vulnerable to the Acropalypse vulnerability (CVE-2023-21036). It leverages the `acropalypse` library to recover trailing pixel data from vulnerable PNG files, supporting both Windows Snipping Tool and Google Pixel profiles.
This repository contains an X-Ways Forensics (XWF) extension designed to detect image files vulnerable to CVE-2023-21036 (Acropalypse). It marks affected files as 'notable' but does not include exploit code for recovering cropped data.
This repository contains a scanner for detecting CVE-2023-21036, a vulnerability in image cropping tools that can leak sensitive data from cropped images. It includes both Go and Python implementations to scan directories for potentially vulnerable PNG and JPEG files.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N