← back
CVE-2013-4787

CVE-2013-4787

35Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 59%
from disclosure to weapon0 days
Published on NVDJul 9
1st PoCJul 3
exploitation probability
59%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrary code via an application package file (APK) that is modified in a way that does not violate the cryptographic signature, probably involving multiple entries in a Zip file with the same name in which one entry is validated but the other entry is installed, aka Android security bug 8219321 and the "Master Key" vulnerability.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.