EIP-2026-100034

PRE-CVE

LG G4 - lghashstorageserver Directory Traversal

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100034. PoCs published by Google Security Research.

AI-analyzed exploit summary The exploit demonstrates a path traversal vulnerability in the LG G4's lghashstorageserver binder service, allowing arbitrary file read/write operations. The PoC reads /proc/self/attr/current by sending crafted binder transactions with traversal sequences (../../).

Description

LG G4 - lghashstorageserver Directory Traversal

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdosandroid
https://www.exploit-db.com/exploits/41352

The exploit demonstrates a path traversal vulnerability in the LG G4's lghashstorageserver binder service, allowing arbitrary file read/write operations. The PoC reads /proc/self/attr/current by sending crafted binder transactions with traversal sequences (../../).

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: LG G4 lghashstorageserver (Android binder service)
No auth needed
Prerequisites: Access to the Android device's binder interface · LG G4 device with vulnerable lghashstorageserver
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026