Vulnerability record · CVE-2013-4787 · published 9 July 2013
CVE-2013-4787: Android APK signature verification bypass allows code execution
Google · Android
Android 1.6 through 4.2 does not properly verify cryptographic signatures for applications, so a crafted APK can pass validation while installing modified code. Known as the Android "Master Key" bug (bug 8219321), it undermines the trust model that signed apps are unmodified.
Description
Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrary code via an application package file (APK) that is modified in a way that does not violate the cryptographic signature, probably involving multiple entries in a Zip file with the same name in which one entry is validated but the other entry is installed, aka Android security bug 8219321 and the "Master Key" vulnerability.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows arbitrary code execution through a signed-app bypass and has very high EPSS, though it is not in KEV and requires user installation of a malicious APK.
What it is
Android 1.6 through 4.2 does not properly verify cryptographic signatures for applications, so a crafted APK can pass validation while installing modified code. Known as the Android "Master Key" bug (bug 8219321), it undermines the trust model that signed apps are unmodified.
Impact
An attacker can execute arbitrary code with the privileges of the installed application, potentially taking over the app's data and permissions on the device.
Attack surface
Reached by delivering a tampered APK to the device, typically via a third-party app store, sideloading, or a malicious update; no special authentication is required, but the user must install the package.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.5892, 99th percentile), indicating elevated likelihood of exploitation activity; reference tags provide no exploit-specific metadata.
What to do
- Apply the Android platform fix and any OEM updates for affected Android 1.6 through 4.2 devices.
- Restrict installation to trusted sources and disable sideloading of unknown APKs where policy allows.
- Use mobile threat defense or app scanning that detects APKs with duplicate Zip entries or signature anomalies.
- Retire or isolate devices that cannot receive the patch, since the platform flaw cannot be mitigated at the app layer alone.
Detection
- Scan installed and incoming APKs for duplicate filenames within the Zip archive, a known indicator of this bypass.
- Monitor for APKs whose signing certificate validates but whose contents differ from the expected build hash.
- Alert on installation of apps from untrusted sources or unexpected package updates on managed devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-4787 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-4787), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.