CVE-2014-7953 describes a race condition in the Android 4.4.4 ActivityManagerService, specifically within the bindBackupAgent method, allowing local users with adb shell access to execute arbitrary code or any valid package as the system user. This high-severity vulnerability (CVSS 7.0) requires a low-privileged attacker to exploit a race condition during package installation, simultaneously monitoring logcat for a specific event to trigger the malicious execution. While the potential impact includes high confidentiality, integrity, and availability compromise, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.4.4CPE matchmatch criteria | cpe:2.3:o:google:android:4.4.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.