Pentesting with Kali Linux
24.1K subscribers
19 photos
262 files
312 links
Download Telegram
Analysis of use-after-free in Binder vulnerability - CVE-2019-2215

This exploit was used in-the-wild to install NSO group malware - Pegasus.
The bug is a local privilege escalation vulnerability that allows for a full compromise of a vulnerable device. If chained with a browser renderer exploit, this bug could fully compromise a device through a malicious website.
https://googleprojectzero.blogspot.com/2019/11/bad-binder-android-in-wild-exploit.html
Channel name was changed to «Pentesting with Kali Linux»