An American security researcher has published proof-of-concept code on GitHub for a recently released Android zero-day.
The zero-day was discovered by security researchers from Google Project Zeroearlier in October. According to Google, this zero-day had already been exploited by hackers.

After the discovery of CVE-2019-2215, Google security researcher Maddie Stone published proof-of-concept (PoC) code. However, the code granted read or write access to the kernel.
A PoC that does just that was published yesterday by Grant Hernandez, a PhD candidate at the University of Florida's Florida Institute of Cyber Security. The PoC, codenamed Qu1ckR00t, can bypass DAC and Linux , and can disable SELinux, SECCOMP (Secure Computing Mode), and MAC (Mandatory Access Control).
The code has been released on GitHub, in source code form rather than as an APK file (an app ). Users will have to complete it themselves, but upon completion, they will have access to an app that can be exploited on an Android smartphone with a single click.
Hernandez claims that Qu1ckR00t has only been tested with Pixel 2 and warns inexperienced users to stop playing with the code, as they risk bricking their operating system and losing data.

Such a tool can only have disadvantages. With its release, cybercriminals have the ability to study the code, as well as users. This could potentially lead to malicious apps that allow access to Android devices, spyware, trojans, ransomware, etc.
To avoid any issues, users are advised to install the necessary patches. Google has released patches for the CVE-2019-2215 vulnerability in the Android security bulletin for October.
Devices running Android 8.x and later are considered vulnerable.
