CVE-2019-15360
The Hisense U965 Android device with a build fingerprint of Hisense/U965_4G_10/HS6739MT:8.1.0/O11019/Hisense_U965_4G_10_S01:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15360?
The severity of CVE-2019-15360 is considered moderate due to the potential for unauthorized access via co-located apps.
How do I fix CVE-2019-15360?
To fix CVE-2019-15360, update the firmware of the Hisense U965 device to a version that addresses this vulnerability.
What devices are impacted by CVE-2019-15360?
CVE-2019-15360 specifically impacts the Hisense U965 Android device with the specified build fingerprint.
What type of vulnerability is CVE-2019-15360?
CVE-2019-15360 is a vulnerability that involves a pre-installed application allowing unauthorized access to device resources.
Can CVE-2019-15360 be exploited remotely?
CVE-2019-15360 requires local access to the device to exploit, meaning it cannot be easily exploited remotely.