
Android CVE-2024-0044, 43093, 23706 zafiyet analizi ve PoC lab ortamΔ±
| Name and Surname | Keyvan Arasteh |
|---|---|
| GitHub | @keyvanarasteh |
| [email protected] | |
| keyvanarasteh | |
| Web Site | qline.tech |
| Name and Surname | Baha Furkan YΔ±ldΔ±z |
|---|---|
| Student No | 2520****1009 |
| Course Name | Penetration Testing |
|---|---|
| Course Code | BGT006 |
| Credit | 3 ECTS |
| Prerequisites | Network Fundamentals, Linux CLI |
| Semester | 2025-2026 Spring |
This project was developed as the final assignment for the Penetration Testing (BGT006) course of the Information Security Technology program at Δ°stinye University. Within the scope of the project, 3 different current vulnerabilities affecting the Android ecosystem (CVE-2024-0044, CVE-2024-43093, CVE-2024-23706) were examined in depth, an isolated lab environment was set up, and analyzed using a cyber detective methodology.
Traditional Android security analyses usually consist only of theoretical documentation or static images. This project solves the following fundamental problems by combining the attack and defense cycle with working code:
exploit_sim.py) end-to-end with the blue team log monitoring detector (detector.py).Single-command PoC launchers (run_poc.bat / run_poc.sh) have been added so that a user who clones the project can run it and see the output within seconds. These scripts simulate the red team's exploitation steps and cause the blue team detector to generate alarms and write to the reports/detection_results.json file. For detailed execution steps, please refer to the Installation and Execution section.
| CVE Code | Vulnerability Type | CVSSv3 Score | Affected Component | Attack Vector |
|---|---|---|---|---|
| CVE-2024-0044 | Run-as UID Bypass (LPE & RCE) | 8.8 (High) | Android System Server | Local (ADB / Malicious App) |
| CVE-2024-43093 | SQLite & DocumentProvider Bypass | 7.8 (High) | Android SQLite Library | Local (Media/File Access) |
| CVE-2024-23706 | Package Manager Bypass | 7.8 (High) | Android Package Manager | Local (App Installation) |
The endpoint log analysis agent src/detector.py developed within the project scope has been integrated into the NetVanguard central anomaly monitoring and alarm panel implemented as the midterm project. Critical vulnerability signatures generated on the emulator are transmitted over the network to the NetVanguard backend engine, simulating a centralized monitoring (SIEM) architecture.
The vulnerability detection agent (src/detector.py) is a lightweight endpoint log monitoring engine designed to detect exploitation activities performed on an Android device.
adb connect command to monitor device logs live.adb logcat | python src/detector.py architecture..log) line by line.DETECTION_KEYWORDS variable in the .env file.[DANGER - ALARM] instantly on the terminal and in logs when it captures critical exploitation signatures such as Android Runtime crashes (SIGSEGV), package installation errors (SIGABRT), and crashing security applications (Process has died).| Technology | Purpose of Use |
|---|---|
| Python 3.x | Detection engine, attack simulation |
| Android SDK / ADB | Emulator management, device communication |
| Docker | Isolated lab environment containerization |
| Flask | Web monitoring panel |
| Logcat | Android system log analysis |