Sploitus

Exploit for Out-of-bounds Write in Google Android

githubexploit Β· 2022-01-17

Exploit Code

README12 lines
## https://sploitus.com/exploit?id=63BCE1C8-DA74-54A4-8C79-BD5441552D99
# Skeleton (but pronounced like Peloton)

A Zero-Click RCE exploit for CVE-2021-0326 on the Peloton Bike 

And also every other unpatched Android Device 

PoC requires ASLR to be disabled.

Associated blog post: https://www.nowsecure.com/blog/2022/02/09/a-zero-click-rce-exploit-for-the-peloton-bike-and-also-every-other-unpatched-android-device/

![diagram of exploit](eloop.svg)