Junglewise Threat Intelligence

CVE-2016-10139: BLU R1 HD Privilege Escalation and Data Exfiltration in Adups FOTA

CVE-2016-10139 · Severity: high · CVSS 7.8 · Published 2017-01-13

Technologies: Adups Fota, BLU R1 HD. Vendors: Adups, BLU.

Executive brief

A security issue was identified in BLU R1 HD mobile devices using Shanghai Adups software, which is responsible for wireless updates. The software contains components that run with high-level system privileges, allowing it to bypass standard security protections. This enables the silent collection and transmission of sensitive user data, including text messages, call logs, and device identifiers, to external servers without the user's knowledge or consent.

Technical details

The vulnerability exists within the Shanghai Adups FOTA (Firmware Over-The-Air) update software on BLU R1 HD devices. The component 'com.adups.fota.sysoper' incorrectly uses the 'android:sharedUserId' attribute set to 'android.uid.system', granting it pervasive system-level permissions. This component acts as a provider ('com.adups.fota.sysoper.provider.InfoProvider') that allows the 'com.adups.fota' app to access sensitive data including SMS content, call logs, and IMSI/IMEI identifiers. The software is designed to exfiltrate this personally identifiable information (PII) every 72 hours, triggered by system events such as charging or network changes, without user interaction.

Affected products

  • BLU R1 HD Shanghai Adups software

Timeline

  • 2016-11-16: disclosed: Public media coverage of the Adups software behavior
  • 2017-01-13: advisory: NVD publication date

References

Related threats