Skip to content

Metasploit ships single-click exploit for Android

community.rapid7.com
4 pointsburlyscudd2 comments
On HN

Comments

Scan a QR code, click the link --- aaaaand attacker has a shell on your phone.

While it's a rather ancient vulnerability (654 days at the least, according to the references), the Metasploit module is new. Metasploit versions of exploits tends to raise the profile of bugs, so hopefully the vendors will pay attention and maybe even come up with a solution for not selling brand new phones with old OSes.

(FD: I worked on this module a wee bit)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.