Executive brief
The Red Magic 11 Pro smartphone contains a security flaw that allows standard, low-privilege apps to perform restricted system actions. An attacker could use a malicious app installed on the device to modify system settings or write unauthorized files to protected storage areas. This could lead to a total compromise of the device's integrity and the exposure of sensitive user data.
Technical details
A privilege management vulnerability (CWE-269) exists in the Red Magic 11 Pro (NX809J) due to a lack of validation for applications accessing a specific service interface. A local attacker with low privileges can exploit this by interacting with the unprotected interface to perform sensitive operations. Successful exploitation allows the attacker to write files to restricted partitions and set writable system properties, potentially leading to full system compromise. The vulnerability is addressed in firmware version GEN_NEEA_NX809JV1.0.0B16MR1.
Affected products
- ZTE Red Magic 11 Pro (NX809J) Firmware versions before GEN_NEEA_NX809JV1.0.0B16MR1
Timeline
- 2026-04-17: disclosed
- 2026-04-17: advisory