Executive brief
A security issue was identified in BLU R1 HD mobile devices using Shanghai Adups software, which is responsible for wireless updates. The software contains components that run with high-level system privileges, allowing it to bypass standard security protections. This enables the silent collection and transmission of sensitive user data, including text messages, call logs, and device identifiers, to external servers without the user's knowledge or consent.
Technical details
The vulnerability exists within the Shanghai Adups FOTA (Firmware Over-The-Air) update software on BLU R1 HD devices. The component 'com.adups.fota.sysoper' incorrectly uses the 'android:sharedUserId' attribute set to 'android.uid.system', granting it pervasive system-level permissions. This component acts as a provider ('com.adups.fota.sysoper.provider.InfoProvider') that allows the 'com.adups.fota' app to access sensitive data including SMS content, call logs, and IMSI/IMEI identifiers. The software is designed to exfiltrate this personally identifiable information (PII) every 72 hours, triggered by system events such as charging or network changes, without user interaction.
Affected products
- BLU R1 HD Shanghai Adups software
Timeline
- 2016-11-16: disclosed: Public media coverage of the Adups software behavior
- 2017-01-13: advisory: NVD publication date