Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Likely ACE vulnerability when restoring backup #1049

Open
Rudxain opened this issue Dec 16, 2024 · 0 comments
Open

Likely ACE vulnerability when restoring backup #1049

Rudxain opened this issue Dec 16, 2024 · 0 comments
Labels
bug Something isn't working

Comments

@Rudxain
Copy link
Contributor

Rudxain commented Dec 16, 2024

@0x192

Describe the bug
If a user restores an arbitrary backup, the backup file could run arbitrary adb shell commands on the Android device.

I originally discovered the vulnerability while refactoring UADNG.

See also Universal-Debloater-Alliance/universal-android-debloater-next-generation#760

Expected behavior
The backup file is supposed to declaratively specify the package states

You have a solution?
Check the cmds in the backup file, and only run each one if it changes the package state.

In the meantime, users should only restore backups they created. Never apply the ones from other users

@Rudxain Rudxain added the bug Something isn't working label Dec 16, 2024
@Rudxain Rudxain changed the title Likely RCE vulnerability Likely RCE when restoring backup Dec 16, 2024
@Rudxain Rudxain changed the title Likely RCE when restoring backup Likely ACE when restoring backup Dec 31, 2024
@Rudxain Rudxain changed the title Likely ACE when restoring backup Likely ACE vulnerability when restoring backup Dec 31, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant