Arbitrary Command Execution Vulnerability in Tecno Android Device
CVE-2019-15344
8.1HIGH
What is CVE-2019-15344?
The Tecno Camon iClick Android device features a pre-installed app that exposes an exported service, allowing any app on the device to execute arbitrary commands as the system user. This vulnerability enables unauthorized access to sensitive device functions—potential attacks include screen recording, factory resets, and extracting user notifications or text messages. Additionally, due to the app's inability to be disabled and the risk of Man-in-the-Middle attacks, attackers can inject malicious commands into network responses, compounding the security risks posed to users.