← Vulnerability feed

Vulnerability record · CVE-2013-4787 · published 9 July 2013

CVE-2013-4787: Android APK signature verification bypass allows code execution

Google · Android

Android 1.6 through 4.2 does not properly verify cryptographic signatures for applications, so a crafted APK can pass validation while installing modified code. Known as the Android "Master Key" bug (bug 8219321), it undermines the trust model that signed apps are unmodified.

9.3 CVSS 2.0 High EPSS 13% · top 3.7% CWE-310 · CWE-310
9.3CVSS 2.0 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrary code via an application package file (APK) that is modified in a way that does not violate the cryptographic signature, probably involving multiple entries in a Zip file with the same name in which one entry is validated but the other entry is installed, aka Android security bug 8219321 and the "Master Key" vulnerability.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw allows arbitrary code execution through a signed-app bypass and has very high EPSS, though it is not in KEV and requires user installation of a malicious APK.

What it is

Android 1.6 through 4.2 does not properly verify cryptographic signatures for applications, so a crafted APK can pass validation while installing modified code. Known as the Android "Master Key" bug (bug 8219321), it undermines the trust model that signed apps are unmodified.

Impact

An attacker can execute arbitrary code with the privileges of the installed application, potentially taking over the app's data and permissions on the device.

Attack surface

Reached by delivering a tampered APK to the device, typically via a third-party app store, sideloading, or a malicious update; no special authentication is required, but the user must install the package.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.5892, 99th percentile), indicating elevated likelihood of exploitation activity; reference tags provide no exploit-specific metadata.

What to do

  • Apply the Android platform fix and any OEM updates for affected Android 1.6 through 4.2 devices.
  • Restrict installation to trusted sources and disable sideloading of unknown APKs where policy allows.
  • Use mobile threat defense or app scanning that detects APKs with duplicate Zip entries or signature anomalies.
  • Retire or isolate devices that cannot receive the patch, since the platform flaw cannot be mitigated at the app layer alone.

Detection

  • Scan installed and incoming APKs for duplicate filenames within the Zip archive, a known indicator of this bypass.
  • Monitor for APKs whose signing certificate validates but whose contents differ from the expected build hash.
  • Alert on installation of apps from untrusted sources or unexpected package updates on managed devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-4787 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-58704Android Cellular Modem improper authorization allows adjacent privilege escalationAndroid's Cellular Modem component contains a logic error that bypasses permission checks, allowing an attacker within radio/adjacent range to escala…KEVEPSS 0.59%analysed8.8CVE-2025-48543Android use-after-free allows Chrome sandbox escape to system_serverA use-after-free in multiple Android locations lets an attacker escape the Chrome sandbox and reach the Android system_server process. Because the fl…KEVEPSS 0.54%analysed8.4CVE-2025-48595Android Framework integer overflow enables local code executionAn integer overflow in multiple locations of the Android Framework can be turned into code execution. It allows a local attacker to escalate privileg…KEVEPSS 1.7%analysed7.8CVE-2025-48572Android Framework permissions bypass enables background activity launchMultiple locations in the Android Framework allow activities to be launched from the background because of a permissions bypass, a missing authentica…KEVEPSS 0.26%analysed7.8CVE-2024-32896Android Pixel logic error allows local privilege escalationCVE-2024-32896 is a logic error in Android (CWE-670/CWE-783) that permits a local attacker to bypass intended restrictions and escalate privileges. I…KEVEPSS 3.0%analysed7.8CVE-2024-29748Android Pixel logic error allows local privilege escalationCVE-2024-29748 is a logic error in Android code that permits bypassing a security check, leading to local escalation of privilege. It affects Google …KEVEPSS 0.67%analysed7.8CVE-2023-35674Android WindowState logic error allows background activity launch and privilege escalationA logic error in onCreate of WindowState.java in the Android Framework lets a background activity be launched, enabling local escalation of privilege…KEVEPSS 2.6%analysed7.8CVE-2023-20963Android WorkSource parcel mismatch local privilege escalationCVE-2023-20963 is a parcel mismatch in Android's WorkSource component that allows a local attacker to escalate privileges without additional executio…KEVEPSS 1.5%analysed

Source: NIST National Vulnerability Database (record CVE-2013-4787), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.