remote code execution when open a project in android studio that google refused to fix(still 0day)

Posted by houjingyi on Dec 21

Video and POC here : https://www.youtube.com/watch?v=hAPkSGxh9H0

When you open a project in android studio, if gradle-wrapper.properties set
distributionUrl=https://
services.gradle.org/distributions/gradle-2.6-all.zip
<https://www.google.com/url?q=http://services.gradle.org/distributions/gradle-2.6-all.zip&sa=D&usg=AFQjCNHSuog_mDHXLFUDcfXdMkVSqzfLug>,
then android studio will download and extract gradle-2.6-all.zip, jar file
in…

If you like the site, please consider joining the telegram channel or supporting us on Patreon using the button below.

Patreon

Original Source