The Chainfire SuperSU package before 1.69 for Android allows attackers to gain privileges via the (1) backtick or (2) $() type of shell metacharacters in the -c option to /system/xbin/su.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Supersu | Chainfire | 1.69 (including) | 1.69 (including) |