Zero-day vulnerability in Google Android

Security bypass
CVE-2013-7372

The vulnerability in Android's component Apache Harmony led to multiple compromises of a bitcoin transactions.

Vulnerability details

Advisory: SB2013081101 - Security bypass in Google Android

Vulnerable component: Google Android

CVE-ID: CVE-2013-7372

CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C

CWE-ID: CWE-310 - Cryptographic Issues

Description:

The vulnerability allows a renote attacker to bypass security restriction on the target system.

The weakness is due to the use of an incorrect offset value by the engineNextBytes function in Apache Harmony, as used in the Java Cryptography Architecture (JCA) in Android . A remote attacker can leverage the resulting PRNG predictability, defeat cryptographic protection mechanisms and launch further attacks on the system.

Successful exploitation of the vulnerablity results in security bypass on the vulnerable system.