TGViewer
Android Security & Malware Android Security & Malware @androidmalware · 44.7K subscribers
Post #2172 9.55K
Bypassing the "run-as" debuggability check on Android via newline injection (CVE-2024-0044)
Attack scenario: A local attacker with ADB shell access to an Android 12 or 13 device with Developer Mode enabled can exploit the vulnerability to run code in the context of any non-system-UID app. From there, the attacker can do anything the app can, like access its private data files or read the credentials it’s stored in AccountManager
https://rtx.meta.security/exploitation/2024/03/04/Android-run-as-forgery.html
Meta Red Team X Bypassing the “run-as” debuggability check on Android via newline injection An attacker with ADB access to an Android device can trick the “run-as” tool into believing any app is debuggable. By doing so, they can read and write private data and invoke system APIs as if they were most apps on the system—including many privileged apps…
  • 👍 11
  • 🔥 2
More from @androidmalware
  1. Oct 7, 2026CVE-2026-23866: Finding a Whatsapp NDay https://numb3rs.re/posts/cve-2026-23866-finding-a-…
  2. Oct 1, 2026CVE-2026-86950: The Great Glyph Grift An in-the-wild iOS bug with a possible WhatsApp zero…
  3. Sep 29, 2026CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability…
  4. Sep 29, 2026How we found 24 Android vulnerabilities using our open source AI security agent https://gi…
  5. Sep 29, 2026From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat https://www.cl…
  6. Sep 28, 2026apk-reverse: An Agent Skill for Android APK reverse engineering, debloating, ad removal, s…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →