PT-2017-7764 · Blu+1 · Blu R1 Hd+1

Tom Karygiannis

·

Published

2017-01-13

·

Updated

2017-03-16

·

CVE-2016-10139

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions BLU R1 HD devices with Shanghai Adups software
Description An issue was discovered that allows for the exfiltration of user data. The com.adups.fota.sysoper app executes as the system user due to its android:sharedUserId attribute being set to android.uid.system, granting it powerful permissions. This app provides the com.adups.fota app access to the user's call log, text messages, and device identifiers through the com.adups.fota.sysoper.provider.InfoProvider component. The exfiltration of personally identifiable information (PII) occurs every 72 hours, triggered by events such as the device being plugged in to charge or when the user leaves or enters a wireless network, all without requiring user interaction.
Recommendations For BLU R1 HD devices with Shanghai Adups software, consider disabling the com.adups.fota.sysoper app to prevent the exfiltration of user data until a fix is available. Additionally, restrict access to the com.adups.fota.sysoper.provider.InfoProvider component to minimize the risk of exploitation. Avoid using the device for sensitive activities until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10139

Affected Products

Blu R1 Hd
Shanghai Adups