Executive brief
A pre-installed system application on certain BLU mobile devices contains a security flaw that allows other apps or network attackers to take control of the phone. This software, which cannot be disabled by the user, can be exploited to record the screen, take photos, install unauthorized apps, or factory reset the device. This puts personal data, privacy, and device availability at significant risk.
Technical details
The com.adups.fota.sysoper application is installed as a system app with the 'android.uid.system' shared user ID, granting it high privileges. It exposes a broadcast receiver, 'WriteCommandReceiver', which is exported and accessible to any local application, allowing them to send intents that execute commands as the system user. Additionally, the 'TaskService' component fetches commands over unencrypted HTTP from a remote server, making the device vulnerable to Man-in-the-Middle (MITM) attacks where a network attacker can inject and execute arbitrary system-level commands. Exploitation can lead to screen recording, unauthorized app installation, and full device resets.
Affected products
- BLU Advance 5.0
- BLU R1 HD
- Shanghai Adups Technology FOTA sysoper
Timeline
- 2016-11-16: disclosed: Media coverage of Adups software security issues
- 2017-01-13: advisory: NVD publication date