CVE ID | CVE-2024-10576 |
Publication date | 04 December 2024 |
Vendor | Infinix Mobile |
Product | com.transsion.agingfunction |
Vulnerable versions | 13 |
Vulnerability type (CWE) | Improper Verification of Intent by Broadcast Receiver (CWE-925) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Infinix Mobile com.transsion.agingfunction
software and participated in coordination of its disclosure.
Infinix devices contain a preloaded com.transsion.agingfunction
application vulnerable to CVE-2024-10576, that exposes an unsecured broadcast receiver. An attacker can
communicate with the receiver and force the device to perform a factory reset without any Android system permissions.
After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.
Credits
We thank Szymon Chadam for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.