Exposed Screen Capture Feature in Sony Xperia L1 Android Device
CVE-2018-14983
5.5MEDIUM
What is CVE-2018-14983?
The Sony Xperia L1 Android device is vulnerable due to a flaw in the system_server process which allows malicious apps, co-located on the device, to take unauthorized screenshots. This is achieved through an exported broadcast receiver in the android framework. The capturing process is not transparent to users, raising significant privacy concerns since it can also capture private notifications, including sensitive information from two-factor authentication. Additionally, the attacking app can use the EXPAND_STATUS_BAR permission to wake the device and access the status bar while the device is locked. Once exploited, a local Denial of Service (DoS) could further compromise user experience by forcing the device to reboot.