Junglewise Threat Intelligence

CVE-2016-10136: BLU R1 HD privilege escalation in Adups FOTA software

CVE-2016-10136 · Severity: high · CVSS 7.8 · Published 2017-01-13

Technologies: Adups Fota, BLU R1 HD. Vendors: Adups, BLU.

Executive brief

A security flaw in the Adups software pre-installed on BLU R1 HD mobile devices allows malicious apps to gain full control over the phone's system. An attacker could use this to read private text messages, steal account login tokens, and delete critical system files. This compromise could lead to total loss of privacy and device functionality for the user.

Technical details

The Adups FOTA application (com.adups.fota.sysoper) on BLU R1 HD devices contains an insecurely configured Content Provider named com.adups.fota.sysoper.provider.InfoProvider. Because the application is configured with the 'android.uid.system' shared user ID, it executes with elevated system privileges. Any third-party application installed on the device can interact with this provider to perform file operations (read/write/delete) as the system user. This allows attackers to modify secure settings to intercept notifications or access the accounts database to steal authentication tokens.

Affected products

  • BLU R1 HD Shanghai Adups software

Timeline

  • 2016-11-16: disclosed: Public reporting on Adups software security issues
  • 2017-01-13: advisory: NVD publication date

References

Related threats