Junglewise Threat Intelligence

CVE-2016-10137: BLU R1 HD privilege escalation in Adups FOTA InfoProvider

CVE-2016-10137 · Severity: high · CVSS 7.8 · Published 2017-01-13

Technologies: Adups Fota, BLU R1 HD. Vendors: Adups, BLU.

Executive brief

A security vulnerability was identified in BLU R1 HD mobile devices running Shanghai Adups software. A pre-installed system application allows other apps on the phone to bypass standard security protections to read, write, or delete sensitive user data. This could allow a malicious app to steal private information such as text messages, call logs, and other personally identifiable information without the user's knowledge.

Technical details

The vulnerability exists in the com.adups.fota.sysoper.provider.InfoProvider content provider within the com.adups.fota.sysoper package. The application is configured with the android:sharedUserId attribute set to 'android.uid.system', causing it to execute with elevated system privileges. Because the content provider is improperly secured, any third-party application installed on the device can interact with it to perform file operations (read, write, delete) as the system user. This allows for the unauthorized extraction of PII, including SMS messages and call logs, by bypassing the Android permission model.

Affected products

  • BLU R1 HD Shanghai Adups software

Timeline

  • 2016-11-16: disclosed: Public media coverage of Adups software issues
  • 2017-01-13: advisory: NVD publication date

References

Related threats