
Exploit app for CVE-2021-39670 and CVE-2021-39690, two permanent denial-of-service vulnerabilities in Android's wallpaper system
This app demonstrates two high severity permanent denial-of-service vulnerabilities in Android's WallpaperManagerService that I discovered: CVE-2021-39670 and CVE-2021-39690.
After running either exploit, the device will keep repeatedly crashing and rebooting.
Write-up coming soon! :)
setStream API in WallpaperManager to exhaust device memory by setting a malicious bitmap file as the wallpaper.WallpaperManagerService, and adding a file-based recovery system in case wallpaper still fails to be decoded.SurfaceFlinger or exhaust device memory.SurfaceFlinger, and then fully mitigated by adding a padding limit in WallpaperManager.As far as I'm aware devices bricked due to these vulnerabilities can't be fixed except through factory reset. Please run this app at your own risk. Note that this project is provided for educational purposes only; please don't use it for malicious activities.