PT-2024-13530 · Unknown · Com.Bdrm.Superreboot
Published
2024-02-05
·
Updated
2024-02-13
·
CVE-2023-47889
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
com.bdrm.superreboot version 1.0.3
Description
The Android application exposes several critical actions through its exported broadcast receivers, allowing any app on the device to send unauthorized broadcasts. This can lead to unintended consequences, including powering off, system reboot, and entering recovery mode.
Recommendations
For version 1.0.3, consider restricting access to the exported broadcast receivers to prevent unauthorized broadcasts until a patch is available. As a temporary workaround, disabling the affected broadcast receivers can help minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Com.Bdrm.Superreboot