Exported Service Vulnerability in ASUS ZenFone 3 Max Device
CVE-2018-14979
4.7MEDIUM
What is CVE-2018-14979?
The ASUS ZenFone 3 Max contains a pre-installed app that exposes sensitive system data. This vulnerability arises from the app's exported service component, which allows unauthorized access to a bug report, Wi-Fi passwords, and other critical system information. Any application with READ_EXTERNAL_STORAGE permissions can access this sensitive information after it is dumped to external storage, thereby posing serious security risks to users. Mitigating the impact of this vulnerability requires careful management of app permissions and user awareness regarding data privacy.