Skip to content
Branch: master
Find file History
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Permalink
Type Name Latest commit message Commit time
..
Failed to load latest commit information.
payload CVE-2018-4233 exploit Jun 17, 2018
.gitignore CVE-2018-4233 exploit Jun 17, 2018
LICENSE CVE-2018-4233 exploit Jun 17, 2018
Makefile CVE-2018-4233 exploit Jun 17, 2018
NOTES.md Update NOTES.md Jun 23, 2018
README.md Update README.md Jun 17, 2018
gen_shellcode.py
index.html CVE-2018-4233 exploit Jun 17, 2018
pwn_i8.js CVE-2018-4233 exploit Jun 17, 2018
shellcode.in.s CVE-2018-4233 exploit Jun 17, 2018

README.md

!!! NOT USEFUL FOR END USERS !!!

THIS IS ONLY INTERESTING FOR DEVELOPERS, EXPECT NO SUPPORT IN ANY SHAPE OR FORM!

This exploit obtains tfp0 from the WebContent sandbox (i.e. from a website), via two known bugs: CVE-2018-4233 (discovered by saelo, reported via ZDI, exploit by niklasb) and CVE-2018-4243 (empty_list exploit by Ian Beer), both fixed in 11.4.

See pwn_i8.js for details.

I have no plans to work on this more. Stage 2 is closed source for now so people don't write malware, but I'm willing to provide sources to legitimate developers who want to build something awesome with it.

Works best when no other apps are running in the background and phone is left alone for a while before clicking on the final alert. Watch console for stage 2 progress.

You can’t perform that action at this time.