logoalt Hacker News

purplehat_today at 5:06 PM7 repliesview on HN

[flagged]


Replies

charcircuittoday at 5:53 PM

This isn't accurate and is just an AI hallucination.

poguetoday at 5:13 PM

So it sounds like if you don't sideload apps you would not be at risk, correct?

show 1 reply
barrkeltoday at 6:04 PM

Look here: https://vulert.com/vuln-db/CVE-2025-48633

It has to do with setting the device owner, and gaining those powers; enabling / disabling apps, remote wipe, etc.. It's a local privilege escalation attack and doesn't require user interaction.

weberertoday at 6:13 PM

What did you use to make that chart? It looks really nice. Its the first time I've see these ASCII boxes on HN without gaps in the border.

4ndrewltoday at 5:34 PM

Conveniently Google can use this to justify banning installs from unofficial stores.

nutjob2today at 5:32 PM

> The Forbes link unfortunately doesn't say much about how it works.

True, it says almost nothing of value about the exploit, but it does teach us that 30% is almost one in three.

da_grift_shifttoday at 5:42 PM

Is this guy going to make a slop repo for every new CVE in a high-profile product advisory so he can rack up some stars and put this shit on his resume? Jesus fuck.

This is just polluting the namespace and making it harder for blue teamers and incident responders to share IOCs.

His repos either lack a PoC and just contain a README with more emojis than facts; try to pass a public version checker off as a PoC; or invent a non-working PoC in the absence of technical details.

Bullshit asymmetry.