TGViewer
Android Security & Malware Android Security & Malware @androidmalware · 44.7K subscribers
Post #2016 7.46K
In December 2022, Google discovered in-the-wild exploit chain targeting Samsung Android devices used by commercial mobile spyware vendor Variston.
It appears that n-day exploits that were fixed in Google products in 2022 (Chrome), were not fixed yet in Samsung (Samsung browser) and because of that exploited by espionage software in early exploitation stages.
Final stage, describes how attacker achieved execution as system_server (CVE-2023-0266, CVE-2023-26083)
https://googleprojectzero.blogspot.com/2023/09/analyzing-modern-in-wild-android-exploit.html
projectzero.google Analyzing a Modern In-the-wild Android Exploit By Seth Jenkins, Project ZeroIntroductionIn December 2022, Google’s Threat Analysis Group (...
  • ❤ 11
  • 👍 4
More from @androidmalware
  1. Oct 7, 2026CVE-2026-23866: Finding a Whatsapp NDay https://numb3rs.re/posts/cve-2026-23866-finding-a-…
  2. Oct 1, 2026CVE-2026-86950: The Great Glyph Grift An in-the-wild iOS bug with a possible WhatsApp zero…
  3. Sep 29, 2026CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability…
  4. Sep 29, 2026How we found 24 Android vulnerabilities using our open source AI security agent https://gi…
  5. Sep 29, 2026From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat https://www.cl…
  6. Sep 28, 2026apk-reverse: An Agent Skill for Android APK reverse engineering, debloating, ad removal, s…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →