Local Access Control Weakness in Third-Party Android App by com.factory.mmigroup
CVE-2023-38297
What is CVE-2023-38297?
A local access control weakness exists in the com.factory.mmigroup component, found across various Android device models. The vulnerability allows third-party applications to exploit functions exposed by the vulnerable pre-installed app. Due to insufficient access control, these applications can perform potentially harmful actions, such as executing arbitrary AT commands, conducting unauthorized factory resets, leaking sensitive information like IMEI and serial numbers, and controlling device settings without user permissions. The security implications depend on the specific device, but the risks are heightened for devices that utilize affected builds of the com.factory.mmigroup application, which runs with system-level privileges.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
