CVE-2013-4777: Google Android

Medium severity, CVSS 6.9. EPSS: 0.2% chance of exploitation in the next 30 days.

A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that listens for shell commands, which allows local users to gain privileges by interacting with a LocalSocket object.

Affected products

Published 2013-09-25. Last modified 2026-06-16.