Exposed Screen Capture Feature in Sony Xperia L1 Android Device
CVE-2018-14983

5.5MEDIUM

Key Information:

Vendor

Sony

Vendor
CVE Published:
25 April 2019

What is CVE-2018-14983?

The Sony Xperia L1 Android device is vulnerable due to a flaw in the system_server process which allows malicious apps, co-located on the device, to take unauthorized screenshots. This is achieved through an exported broadcast receiver in the android framework. The capturing process is not transparent to users, raising significant privacy concerns since it can also capture private notifications, including sensitive information from two-factor authentication. Additionally, the attacking app can use the EXPAND_STATUS_BAR permission to wake the device and access the status bar while the device is locked. Once exploited, a local Denial of Service (DoS) could further compromise user experience by forcing the device to reboot.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-14983 : Exposed Screen Capture Feature in Sony Xperia L1 Android Device