Impact
Acode versions 1.11.6 through 1.12.7 expose an exported service that accepts a command from any installed Android app. The service passes the received command to Java's ProcessBuilder with "sh -c", executing it under Acode's UID. An attacker can thus run arbitrary shell commands as Acode, gaining access to Acode private data, stored credentials, File‑Picker grants, and any runtime permissions that Acode holds, all without needing any permissions for the malicious app itself.
Affected Systems
The vulnerability affects the Acode app from the Acode‑Foundation publisher, specifically releases between 1.11.6 and 1.12.7 inclusive. Version 1.12.7 includes the fix that removes the exporter without proper permission checks.
Risk and Exploitability
The CVSS score of 8.6 classifies this as a high‑severity flaw. EPSS is unavailable, but the lack of a binding permission means a zero‑permission, local Android application can exploit the vulnerability immediately upon installing. No external network access is required; the attack vector is local. Because the flaw allows remote commands to run within Acode’s process space, it is also a local privilege escalation that can be abused to elevate or compromise user data on the device.
OpenCVE Enrichment