remote code execution when open a project in android studio that google refused to fix(still 0day)

Posted by houjingyi on Dec 21

Video and POC here :

When you open a project in android studio, if set
then android studio will download and extract, jar file

Original Source
