Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
PoCForCVE-2015-1528 — Proof-of-concept exploit for CVE-2015-1528 demonstrating privilege escalation on Android 5.0 via binder call fuzzing, with staged code injection into mediaserver, surfaceflinger, and system_server. | Kitploit
Tools/GitHubGitHub/kanpol/pocforcve-2015-1528
Android SecurityPrivilege EscalationExploitationPost-ExploitationPayload DevelopmentBinary Exploitation
GitHubkanpol/pocforcve-2015-1528

PoCForCVE-2015-1528

Proof-of-concept exploit for CVE-2015-1528 demonstrating privilege escalation on Android 5.0 via binder call fuzzing, with staged code injection into mediaserver, surfaceflinger, and system_server.

View Repository
11811 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

This PoC is divided into three Parts, the folder mediaserver help to inject code into mediaserver from a normal application. the folder surfaceflinger help to inject code to surfaceflinger after you got mediaserver permission. the folder system_server help to inject code to system_server after you got surfaceflinger permission. the bbshell folder help to inject busybox to mediaserver

the PoC contain many hard codes, I tested it on Nexus 5 for Android 5.0(LRX21O), you may have to adust these hard codes to suit your case. detail introduce about the vulnerability please refer to https://www.blackhat.com/docs/us-15/materials/us-15-Gong-Fuzzing-Android-System-Services-By-Binder-Call-To-Escalate-Privilege-wp.pdf

Download Tool