PT-2024-12696 · Motorola+1 · Motorola Moto G Power+3
Published
2024-04-22
·
Updated
2024-11-01
·
CVE-2023-38291
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
TCL 30Z (affected versions not specified)
TCL 10L (affected versions not specified)
Motorola Moto G Pure (affected versions not specified)
Motorola Moto G Power (affected versions not specified)
Description
An issue was discovered in a third-party component related to
ro.boot.wifimacaddr, shipped on devices from multiple device manufacturers. Various software builds for the affected devices leak the Wi-Fi MAC address to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in Android 10 and higher, but in these instances, they are leaked by a high-privilege process and can be obtained indirectly.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Motorola Moto G Power
Motorola Moto G Pure
Tcl 10L
Tcl 30Z