CVE-2018-14997: Medium severity leagoo p1 vulnerability
The Leagoo P1 Android device with a build fingerprint of sp7731c1h1032v4bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains the android framework (i.e., systemserver) with a package name of android that has been modified by Leagoo or another entity in the supply chain. The systemserver process in the core Android package has an exported broadcast receiver that allows any app co-located on the device to programmatically initiate the taking of a screenshot and have the resulting screenshot be written to external storage. The taking of a screenshot is not transparent to the user; the device has a screen animation as the screenshot is taken and there is a notification indicating that a screenshot occurred. If the attacking app also requests the EXPANDSTATUSBAR permission, it can wake the device up using certain techniques and expand the status bar to take a screenshot of the user's notifications even if the device has an active screen lock. The notifications may contain sensitive data such as text messages used in two-factor authentication. The systemserver process that provides this capability cannot be disabled, as it is part of the Android framework. The notification can be removed by a local Denial of Service (DoS) attack to reboot the device.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-14997.
What is the severity level of CVE-2018-14997?
The severity level of CVE-2018-14997 is medium (5.5).
What is affected by CVE-2018-14997?
The Leagoo P1 Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys is affected by CVE-2018-14997.
What is the vulnerability description of CVE-2018-14997?
The Leagoo P1 Android device contains a modified android framework (system_server) package that has been altered by Leagoo or another entity in the supply chain.
Are there any references available for CVE-2018-14997?
Yes, there are references available for CVE-2018-14997. You can find them at the following links: [link1], [link2], [link3].