CVE-2016-10137
The content provider named com.adups.fota.sysoper.provider.InfoProvider in the app with a package name of com.adups.fota.sysoper allows any app on the device to read, write, and delete files as the system user.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sysoper.provider.InfoProvider in the app with a package name of com.adups.fota.sysoper allows any app on the device to read, write, and delete files as the system user. In the com.adups.fota.sysoper app's AndroidManifest.xml file, it sets the android:sharedUserId attribute to a value of android.uid.system which makes it execute as the system user, which is a very privileged user on the device. This allows a third-party app to read, write, and delete the user's sent and received text messages and call log. This allows a third-party app to obtain PII from the user without permission to do so.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- adups/adups fota
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/96852
- https://www.kryptowire.com/adups_security_analysis.htmlTechnical Description, Third Party Advisory
- https://www.nytimes.com/2016/11/16/us/politics/china-phones-software-security.htmlPress/Media Coverage
- http://www.securityfocus.com/bid/96852
- https://www.kryptowire.com/adups_security_analysis.htmlTechnical Description, Third Party Advisory
- https://www.nytimes.com/2016/11/16/us/politics/china-phones-software-security.htmlPress/Media Coverage
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.