Android Zygote Injection Vulnerability Let Attackers Execute Code & Escalate Privileges

The “Zygote Injection” vulnerability affects devices running Android 11 or older and enables attackers to escalate privileges from a shell user to the system user, potentially compromising entire devices. While unprivileged apps cannot alter this setting, security researchers demonstrated that when a malicious actor modifies the hidden_api_blacklist_exemptions setting with injected newlines, they can append arbitrary Zygote commands that the system treats as legitimate commands for process creation. While this vulnerability primarily affects older Android versions, it highlights the importance of proper security boundaries in operating system design. A critical Android vulnerability identified as CVE-2024-31317 has been discovered that allows attackers to execute arbitrary code with system privileges. When an Android device powers on, after the Linux kernel initializes, it launches essential Android services including the Zygote process, which runs with system privileges. The Android Zygote Injection vulnerability demonstrates how seemingly minor input validation issues can lead to system-wide security compromises. The vulnerability targets Android’s Zygote process, a crucial component in the operating system responsible for forking new applications and system processes. Security researchers at Infosec found that Android’s hidden_api_blacklist_exemptions global setting, which allows certain apps to bypass Android’s hidden API restrictions, can be manipulated to inject malicious commands. Users should be cautious as exploiting this vulnerability can cause device bootloops because the modified setting persists across reboots and directly affects how Zygote spawns processes. Android devices should be updated to the latest security patches to mitigate this serious vulnerability, especially since it affects all Android versions up to Android 11. The System Server component does not properly escape newline characters when passing commands to the Zygote process, creating a critical injection point. The vulnerability has been described by security researchers as possibly the most valuable userspace Android vulnerability in recent years. This occurs because System Server’s update() method is called whenever the hidden_api_blacklist_exemptions setting changes, and it passes this setting directly to Zygote without proper sanitization. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis.

This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 11 Mar 2025 08:20:08 +0000


Cyber News related to Android Zygote Injection Vulnerability Let Attackers Execute Code & Escalate Privileges

Android Zygote Injection Vulnerability Let Attackers Execute Code & Escalate Privileges - The “Zygote Injection” vulnerability affects devices running Android 11 or older and enables attackers to escalate privileges from a shell user to the system user, potentially compromising entire devices. While unprivileged apps cannot ...
19 hours ago Cybersecuritynews.com CVE-2024-31317
CVE-2021-36845 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) versions < 1.3.8, there are 46 vulnerable parameters that were missed by the vendor while patching the 1.3.7 version to 1.3.8. ...
3 years ago
What Is Android System WebView and Should You Uninstall It? | Definition from TechTarget - Android developers use WebView when they want to display webpages or Hypertext Markup Language content in a Google app or other application. Android System WebView is a system component for the Android operating system (OS) that enables Android apps ...
5 months ago Techtarget.com
CVE-2007-0228 - The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &CONNECTSERVER& (2) &ADDENTRY& (3) &FIN& (4) &START& (5) ...
7 years ago
CVE-2023-52587 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
Wordfence Intelligence Weekly WordPress Vulnerability Report (September 23, 2024 to September 29, 2024) - Software Name Software Slug 012 Ps Multi Languages 012-ps-multi-languages ABC APP CREATOR abcapp-creator Absolute Reviews absolute-reviews Accordion accordions Ads by WPQuads – Adsense Ads, Banner Ads, Popup Ads quick-adsense-reloaded Advanced File ...
5 months ago Wordfence.com Slug
CVE-2019-13363 - admin.php?pagenotification_by_mail in Piwigo 2.9.5 has XSS via the nbm&#95;send&#95;html&#95;mail, nbm&#95;send&#95;mail&#95;as, nbm&#95;send&#95;detailed&#95;content, ...
2 years ago
CVE-2020-28092 - PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?gTeam&mTask&amy&status3&id,?gTeam&mTask&amy&status0&id,?gTeam&mTask&amy&status1&id,?gTeam&mTask&amy&status10&id ...
4 years ago
Snowblind malware abuses Android security feature to bypass security - A novel Android attack vector from a piece of malware tracked as Snowblind is abusing a security feature to bypass existing anti-tampering protections in apps that handle sensitive user data. Snowblind's goal is to repackage a target app to make them ...
8 months ago Bleepingcomputer.com Medusa
BadBox malware disrupted on 500K infected Android devices - The BadBox Android malware botnet has been disrupted again by removing 24 malicious apps from Google Play and sinkholing communications for half a million infected devices. HUMAN says it also discovered 24 Android apps in the official app store, ...
6 days ago Bleepingcomputer.com
AutoSpill attack steals credentials from Android password managers - Security researchers developed a new attack, which they named AutoSpill, to steal account credentials on Android during the autofill operation. In a presentation at the Black Hat Europe security conference, researchers from the International ...
1 year ago Bleepingcomputer.com
CVE-2018-14825 - On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OS 6.0, CN75 running Android OS 6.0, CN75e running Android OS 6.0, CT50 running Android OS 6.0, D75e running ...
5 years ago
CVE-2018-16371 - PESCMS Team 2.2.1 has multiple reflected XSS via the keyword parameter: gTeam&mUser&aindex&keyword, gTeam&mUser_group&aindex&keyword, gTeam&mDepartment&aindex&keyword, and ...
6 years ago
Dual Privilege Escalation Chain: Exploiting Monitoring and Service Mesh Configurations and Privileges in GKE to Gain Unauthorized Access in Kubernetes - While each issue might not result in significant damage on its own, when combined they create an opportunity for an attacker who already has access to a Kubernetes cluster to escalate their privileges. If an attacker has the ability to execute in the ...
1 year ago Unit42.paloaltonetworks.com
CVE-2021-47275 - In the Linux kernel, the following vulnerability has been resolved: ...
9 months ago
CVE-2020-10094 - A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC2130 before LW74.GM4.P273; CX510 & XC2132 before LW74.GM7.P273; ...
4 years ago
CVE-2024-36003 - In the Linux kernel, the following vulnerability has been resolved: ...
9 months ago
CVE-2019-13977 - index.php in Ovidentia 8.4.3 has XSS via tggroups, tgmaildoms&idxcreate&userid0&bgrpy, tgdelegat, tgsite&idxcreate, tgsite&item4, tgadmdir&idxmdb&id1, tgnotes&idxCreate, tgadmfaqs&idxAdd, or ...
5 years ago
5 Best VPNs for Android in 2024 - See details VIsit ProtonVPN. see details Visit CyberGhost VPN. As more Android users rely on their smartphones to surf the web, virtual private networks have become essential tools to help secure your mobile connection, no matter where you are. One ...
1 year ago Techrepublic.com
Vulnerability Summary for the Week of January 1, 2024 - Prior to version 1.2.0, there is a potential for a mutation cross-site scripting vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that ...
1 year ago Cisa.gov
CVE-2006-0364 - Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via a signature containing a JavaScript URI in the SRC attribute of an IMG element, in which the URI uses SGML numeric ...
7 years ago
CVE-2022-29422 - Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock plugin < 2.3.2 at WordPress via &ycd-countdown-width, &ycd-progress-height, &ycd-progress-width, ...
2 years ago
New Wave of 'Anatsa' Banking Trojans Targets Android Users in Europe - The campaign has been ongoing for at least four months and is the latest salvo from the operators of the malware, which first surfaced in 2020 and has previously notched victims in the US, Italy, United Kingdom, France, Germany, and other countries. ...
1 year ago Darkreading.com
How Google is Using Clang Sanitizers to Make Android More Secure - Google is committed to making Android the most secure mobile operating system on the market. One of the ways they do this is by using Clang sanitizers to identify and fix vulnerabilities in the Android baseband. Clang sanitizers are a collection of ...
1 year ago Securityboulevard.com
The Exploration of Static vs Dynamic Code Analysis - Two essential methodologies employed for this purpose are Static Code Analysis and Dynamic Code Analysis. Static Code Analysis involves the examination of source code without its execution. In this exploration of Static vs Dynamic Code Analysis, ...
1 year ago Feeds.dzone.com

Cyber Trends (last 7 days)