Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissions.
After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.
CVSS
No CVSS.
References
Configurations
No configuration.
History
04 Dec 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-04 12:15
Updated : 2024-12-04 12:15
NVD link : CVE-2024-10576
Mitre link : CVE-2024-10576
CVE.ORG link : CVE-2024-10576
JSON object : View
Products Affected
No product.
CWE
CWE-925
Improper Verification of Intent by Broadcast Receiver