CVE-2024-10576

Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissions.  After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.
CVSS

No CVSS.

Configurations

No configuration.

History

04 Dec 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-04 12:15

Updated : 2024-12-04 12:15


NVD link : CVE-2024-10576

Mitre link : CVE-2024-10576

CVE.ORG link : CVE-2024-10576


JSON object : View

Products Affected

No product.

CWE
CWE-925

Improper Verification of Intent by Broadcast Receiver