Any competent malware developer must have already figured out how to exploit this the first time around. Now that every single one of those malware developers has learned it is still exploitable, the payload they've spent the past month perfecting can now be deployed in the wild. So, can someone explain why a disastrous worm hasn't already swept the globe and infected 99% of Android devices on the planet within ten m…
There are a couple of reasons:
1) Just because you have an exploit it doesn't guarantee you'll be able to execute code because you still need to bypass ASLR. The PoC's released do not do this.
2) Infecting phones with malware is very rare. The "tech pundits" like to scare the public, but the reality is that smartphones are rarely infected. Besides, the people that write and distribute malware are too busy infecting Windows machines.