{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/android-9.0-13.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*","cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*","cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*","cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2024-31317"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Android (9.0-13.0)"],"_cs_severities":["high"],"_cs_tags":["android","vulnerability","privilege-escalation","zygote"],"_cs_type":"advisory","_cs_vendors":["Google"],"content_html":"\u003cp\u003eA publicly available proof-of-concept (PoC) deployment kit has been released targeting CVE-2024-31317, a high-severity vulnerability (CVSS 7.8) affecting the Android Zygote process. The vulnerability allows an attacker with low-level privileges and the WRITE_SECURE_SETTINGS permission to perform command injection, leading to full system compromise. The released tool automates the process of generating a reverse shell and injecting it into the Zygote process through the manipulation of the 'hidden_api_blacklist_exemptions' global setting. This affects Android versions 9 through 13. Systems are considered protected if they have applied the June 2024 security patch level or later. The availability of this automated deployment script significantly lowers the barrier for exploitation by malicious actors targeting unpatched Android devices.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial access to an Android device with low-level privileges.\u003c/li\u003e\n\u003cli\u003eAttacker obtains or already possesses the WRITE_SECURE_SETTINGS permission on the device.\u003c/li\u003e\n\u003cli\u003eAttacker pushes a malicious \u003ccode\u003epayload.txt\u003c/code\u003e containing the injection string to the \u003ccode\u003e/data/local/tmp/\u003c/code\u003e directory.\u003c/li\u003e\n\u003cli\u003eAttacker invokes \u003ccode\u003eam force-stop com.android.settings\u003c/code\u003e to clear existing settings state.\u003c/li\u003e\n\u003cli\u003eAttacker executes \u003ccode\u003esettings put global hidden_api_blacklist_exemptions \u0026quot;$(cat payload.txt)\u0026quot;\u003c/code\u003e to trigger the injection vulnerability within the Zygote process context.\u003c/li\u003e\n\u003cli\u003eAttacker executes \u003ccode\u003eam start -n com.android.settings/.Settings\u003c/code\u003e to force the Zygote process to process the malicious configuration.\u003c/li\u003e\n\u003cli\u003eThe reverse shell connects back to the attacker-controlled listener, granting arbitrary command execution with elevated privileges.\u003c/li\u003e\n\u003cli\u003eAttacker reverts the global setting by executing \u003ccode\u003esettings put global hidden_api_blacklist_exemptions \u0026quot;null\u0026quot;\u003c/code\u003e to attempt to hide the persistence or modification.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full device compromise, allowing an attacker to bypass security restrictions, access sensitive user data, and execute arbitrary code with elevated system privileges. The vulnerability affects a wide range of Android versions (9-13), placing a large install base at risk if they have not applied the June 2024 security updates.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize the deployment of the June 2024 Android Security Patch Level or higher across the device fleet to mitigate CVE-2024-31317.\u003c/li\u003e\n\u003cli\u003eAudit devices for applications or processes that have been granted the 'android.permission.WRITE_SECURE_SETTINGS' permission, as this is a core requirement for exploitation.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected execution of shell commands from within \u003ccode\u003e/data/local/tmp/\u003c/code\u003e, which is a common staging area for exploit payloads on Android.\u003c/li\u003e\n\u003cli\u003eUse Mobile Device Management (MDM) solutions to enforce patch compliance and restrict the installation of unauthorized applications or tools that can execute arbitrary shell commands.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T17:17:14Z","date_published":"2026-08-25T17:17:14Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2024-31317-android-zygote/","summary":"A public proof-of-concept deployment script for CVE-2024-31317 enables local privilege escalation and arbitrary code execution on Android 9 through 13 by exploiting Zygote process command injection via the global settings API.","title":"Public Exploit Released for Android Zygote CVE-2024-31317","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2024-31317-android-zygote/"}],"language":"en","title":"CraftedSignal Threat Feed - Android (9.0-13.0)","version":"https://jsonfeed.org/version/1.1"}