Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Wallbreak — Exploit app for CVE-2021-39670 and CVE-2021-39690, two permanent denial-of-service vulnerabilities in Android's wallpaper system | Kitploit
Tools/GitHubGitHub/supersonic/wallbreak
Android SecurityVulnerability AnalysisExploitationMobile SecurityLearning & Education
GitHubsupersonic/wallbreak

Wallbreak

Exploit app for CVE-2021-39670 and CVE-2021-39690, two permanent denial-of-service vulnerabilities in Android's wallpaper system

View Repository
16193 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Wallbreak

Download as APK

This app demonstrates two high severity permanent denial-of-service vulnerabilities in Android's WallpaperManagerService that I discovered: CVE-2021-39670 and CVE-2021-39690. After running either exploit, the device will keep repeatedly crashing and rebooting.

Write-up coming soon! :)

CVE-2021-39670 "Stream Exploit"

  • Exploits the setStream API in WallpaperManager to exhaust device memory by setting a malicious bitmap file as the wallpaper.
  • Appears to be very portable across manufacturers and device versions.
  • Patch released in May 2022 Android Security Bulletin.
  • Was patched by using a more efficient wallpaper decoder in WallpaperManagerService, and adding a file-based recovery system in case wallpaper still fails to be decoded.

CVE-2021-39690 "Padding Exploit"

  • Exploits the display padding functionality in some Android phones to either crash SurfaceFlinger or exhaust device memory.
  • I could only reproduce this vulnerability in Pixel devices with animated live wallpapers.
  • Requires Android P or higher.
  • Initial patch released in March 2022 Android Security Bulletin.
  • Was initially patched by adding stricter input validation in SurfaceFlinger, and then fully mitigated by adding a padding limit in WallpaperManager.

As far as I'm aware devices bricked due to these vulnerabilities can't be fixed except through factory reset. Please run this app at your own risk. Note that this project is provided for educational purposes only; please don't use it for malicious activities.

Download Tool