Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.1.13). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. In addition to the local attack surface, its accompanying app with a package name of com.ekesoo.lovelyhifonts makes network requests using HTTP and an attacker can perform a Man-in-the-Middle (MITM) attack on the connection to inject a command in a network response that will be executed as the system user by the com.lovelyfont.defcontainer app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing commands as the system user can allow a third-party app to factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
宇龙计算机通信科技 Coolpad 1851 注入漏洞
Vulnerability Description
宇龙计算机通信科技 Coolpad 1851是中国宇龙计算机通信科技公司的一款智能手机。 宇龙计算机通信科技 Coolpad 1851(build fingerprint:Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys)中的com.lovelyfont.defcontainer存在注入漏洞。攻击者可通过诱使用户打开特制的应用程序利用该漏洞执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A