What happened
Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."
Affected versions
Android Kernel: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 47463Android - Binder Driver Use-After-FreeGoogle Security Research2019-10-04VerifiedExploit-DB 48129Android Binder - Use-After-Free (Metasploit)Metasploit2020-02-24VerifiedPoC-in-GitHub · timwr/CVE-2019-2215★ 79timwr2019-10-04CandidatePoC-in-GitHub · kangtastic/cve-2019-2215Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215★ 136kangtastic2019-10-14CandidatePoC-in-GitHub · ATorNinja/CVE-2019-2215CVE 2019-2215 Android Binder Use After Free★ 4ATorNinja2019-10-17CandidatePoC-in-GitHub · LIznzn/CVE-2019-2215Temproot for Bravia TV via CVE-2019-2215.★ 26LIznzn2020-01-30CandidatePoC-in-GitHub · DimitriFourny/cve-2019-2215Android privilege escalation via an use-after-free in binder.c★ 41DimitriFourny2020-02-17CandidatePoC-in-GitHub · codecat007/CVE-2019-2215★ 0codecat0072020-03-31CandidatePoC-in-GitHub · qre0ct/android-kernel-exploitation-ashfaq-CVE-2019-2215android-kernel-exploitation-ashfaq-CVE-2019-2215 docker setup for mac users★ 7qre0ct2020-04-25CandidatePoC-in-GitHub · sharif-dev/AndroidKernelVulnerabilityTriggering and Analyzing Android Kernel Vulnerability CVE-2019-2215★ 72sharif-dev2020-06-07CandidatePoC-in-GitHub · c3r34lk1ll3r/CVE-2019-2215PoC for old Binder vulnerability (based on P0 exploit)★ 14c3r34lk1ll3r2020-10-27CandidatePoC-in-GitHub · Byte-Master-101/CVE-2019-2215Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215★ 4Byte-Master-1012021-02-05CandidatePoC-in-GitHub · mufidmb38/CVE-2019-2215CVE-2019-2215★ 3mufidmb382021-05-07CandidatePoC-in-GitHub · nicchongwb/Rootsmart-v2.0Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration★ 1nicchongwb2022-02-28CandidatePoC-in-GitHub · CrackerCat/Rootsmart-v2.0Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration★ 2CrackerCat2022-03-25CandidatePoC-in-GitHub · Enceka/cve-2019-2215-3.18for kernel 3.18.x★ 3Enceka2022-04-28CandidatePoC-in-GitHub · elbiazo/CVE-2019-2215Exploit for Bad Binder★ 2elbiazo2023-05-27CandidatePoC-in-GitHub · stevejubx/CVE-2019-2215Android Kernel Vulnerability (CVE-2019-2215) temporary root PoC★ 17stevejubx2023-11-05CandidatePoC-in-GitHub · willboka/CVE-2019-2215-HuaweiP20LiteExploit for CVE-2019-2215 (bad binder) for Huawei P20 Lite★ 5willboka2024-02-04CandidatePoC-in-GitHub · mutur4/CVE-2019-2215This is a critical UAF vulnerability exploit that affected the android binder IPC system used in the wild and discovered by P0★ 6mutur42024-04-15CandidatePoC-in-GitHub · R0rt1z2/huawei-unlockUnlock your Huawei device with ADB (CVE-2019-2215)★ 11R0rt1z22024-05-20CandidatePoC-in-GitHub · raymontag/CVE-2019-2215★ 0raymontag2024-07-02CandidatePoC-in-GitHub · XiaozaYa/CVE-2019-2215Andriod binder bug record★ 0XiaozaYa2024-11-18CandidatePoC-in-GitHub · llccd/TempRoot-HuaweiCVE-2019-2215 poc for Huawei hardened kernel★ 6llccd2025-02-04CandidatePoC-in-GitHub · 0xbinder/android-kernel-exploitation-labThis lab guides you through setting up an environment to explore CVE-2019-2215, a critical Android kernel vulnerability in the binder subsystem.★ 440xbinder2025-03-13CandidatePoC-in-GitHub · mouseos/cve-2019-2215_SH-M08★ 2mouseos2025-04-20CandidatePoC-in-GitHub · i-redbyte/android-badbinder-demodemo CVE-2019-2215 (Bad Binder) for Android Q★ 5i-redbyte2025-11-06CandidatePoC-in-GitHub · wired0ut/CVE-2019-2215Full exploit for the Android vulnerability Bad Binder found in early Google Pixel phones.★ 4wired0ut2026-04-22CandidatePoC-in-GitHub · mythicaltree/CVE-2019-2215★ 0mythicaltree2026-06-23CandidatePoC-in-GitHub · flipphoneguy/root-sonim-xp3800app that ports CVE-2019-2215 to arm32 and mounts a su binary to /sbin with denylist + root app installer. firehose/Magisk guide included★ 11flipphoneguy2026-06-30CandidatePoC-in-GitHub · NESTle19/CVE-2019-2215★ 0NESTle192026-07-19CandidatePoC-in-GitHub · 0xbinder/CVE_2019_2215A rewritten Proof-of-Concept / Local Privilege Escalation (LPE) exploit targeting CVE-2019-2215, a Use-After-Free vulnerability in the Android Binder driver.★ 30xbinder2026-08-10CandidatePoC-in-GitHub · Begitdj/cve-2019-2215-markw★ 1Begitdj2026-08-19CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.