Executive brief
A security vulnerability exists in a factory testing component pre-installed on Motorola mobile devices. A malicious app installed on the phone could exploit this flaw to bypass standard security checks, allowing it to access sensitive user data and modify protected system settings. Users are advised to update their devices to the latest security patch level to resolve this issue.
Technical details
An improper authentication and authorization vulnerability (CWE-306, CWE-285) exists in the Motorola Factory Test component (com.motorola.motocit). The application improperly handles a writable file descriptor in external storage. A local attacker, via a malicious third-party application, can utilize this file descriptor to open a TCP server. This exposure allows the attacker to bypass Android permission models, leading to unauthorized access to sensitive device data and the ability to modify protected system configurations. The issue is resolved in Motorola software versions with a Security Patch Level (SPL) of 2026-04-05 or later.
Affected products
- Motorola Motorola Phones (CIT Test Service) Security Patch Level prior to 2026-04-05
Timeline
- 2026-05-07: disclosed: Initial disclosure date
- 2026-05-19: advisory: NVD publication date
- 2026-04-05: patched: Security Patch Level containing the fix