CVE-2023-38295: High severity Tcl TCL 30Z vulnerability

Published Apr 22, 2024
·
Updated

Certain software builds for the TCL 30Z and TCL 10 Android devices contain a vulnerable, pre-installed app that relies on a missing permission that provides no protection at runtime. The missing permission is required as an access permission by components in various pre-installed apps. On the TCL 30Z device, the vulnerable app has a package name of com.tcl.screenrecorder (versionCode='1221092802', versionName='v5.2120.02.12008.1.T' ; versionCode='1221092805', versionName='v5.2120.02.12008.2.T'). On the TCL 10L device, the vulnerable app has a package name of com.tcl.sos (versionCode='2020102827', versionName='v3.2014.12.1012.B'). When a third-party app declares and requests the missing permission, it can interact with certain service components in the aforementioned apps (that execute with "system" privileges) to perform arbitrary files reads/writes in its context. An app exploiting this vulnerability only needs to declare and request the single missing permission and no user interaction is required beyond installing and running a third-party app. The software build fingerprints for each confirmed vulnerable device are as follows: TCL 10L (TCL/T770B/T1LITE:11/RKQ1.210107.001/8BIC:user/release-keys) and TCL 30Z (TCL/4188R/JettaATT:12/SP1A.210812.016/LV8E:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU5P:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU61:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU66:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU68:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU6P:user/release-keys, and TCL/T602DL/JettaTF:12/SP1A.210812.016/vU6X:user/release-keys). This malicious app declares the missing permission named com.tct.smart.switchphone.permission.SWITCHDATA as a normal permission, requests the missing permission, and uses it to interact with the com.tct.smart.switchdata.DataService service component that is declared in vulnerable apps that execute with "system" privileges to perform arbitrary file reads/writes.

Affected Software

4 affected components
Tcl TCL 30Z
Tcl TCL 10L
android/com.tcl.screenrecorder=v5.2120.02.12008.1.T, =v5.2120.02.12008.2.T
android/com.tcl.sos=v3.2014.12.1012.B

Event History

Apr 22, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-38295?

CVE-2023-38295 has a high severity rating due to the exploitation potential associated with missing permissions in pre-installed apps.

2

How do I fix CVE-2023-38295?

To address CVE-2023-38295, ensure that the affected apps are updated to a version that includes the necessary permissions.

3

What devices are affected by CVE-2023-38295?

CVE-2023-38295 affects certain builds of the TCL 30Z and TCL 10 Android devices that come with vulnerable pre-installed apps.

4

What are the consequences of CVE-2023-38295 if exploited?

Exploitation of CVE-2023-38295 can lead to unauthorized access to sensitive data due to the lack of runtime protection.

5

Is there a workaround for CVE-2023-38295?

As a temporary workaround for CVE-2023-38295, users can uninstall the vulnerable pre-installed apps if they are not essential for device functionality.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203