Rapid7βs Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victimβs machine.
http://packetstormsecurity.com/files/160004/Rapid7-Metasploit-Framework-msfvenom-APK-Template-Command-Injection.html
https://github.com/rapid7/metasploit-framework/pull/14288
https://github.com/rapid7/metasploit-framework/pull/14288
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7384