The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0)) with an exported broadcast receiver app component named com.android.messaging.trackersender.TrackerSender. Any app co-located on the device, even one with no permissions, can send a broadcast intent with certain embedded data to the exported broadcast receiver application component that will result in the programmatic sending of a text message where the phone number and body of the text message is controlled by the attacker.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T09:46:25.317Z

Reserved: 2018-08-05T00:00:00

Link: CVE-2018-14984

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-12-28T21:29:00.307

Modified: 2024-11-21T03:50:15.097

Link: CVE-2018-14984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.