Unsecured Screen Recording Feature in Vivo V7 Android Devices
CVE-2018-15000
6.3MEDIUM
What is CVE-2018-15000?
The Vivo V7 Android device features a platform app that contains an exported service named com.vivo.smartshot.ui.service.ScreenRecordService, allowing unauthorized screen recording for up to 60 minutes. Although a recording notification typically appears, attackers can exploit the system by manipulating service parameters, leading to the potential concealment of this notification from users. Consequently, attackers can record user screens and save files directly to an app's private directory, significantly compromising user privacy.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
