CVE-2023-38295: High severity Tcl TCL 30Z vulnerability
Certain software builds for the TCL 30Z and TCL 10 Android devices contain a vulnerable, pre-installed app that relies on a missing permission that provides no protection at runtime. The missing permission is required as an access permission by components in various pre-installed apps. On the TCL 30Z device, the vulnerable app has a package name of com.tcl.screenrecorder (versionCode='1221092802', versionName='v5.2120.02.12008.1.T' ; versionCode='1221092805', versionName='v5.2120.02.12008.2.T'). On the TCL 10L device, the vulnerable app has a package name of com.tcl.sos (versionCode='2020102827', versionName='v3.2014.12.1012.B'). When a third-party app declares and requests the missing permission, it can interact with certain service components in the aforementioned apps (that execute with "system" privileges) to perform arbitrary files reads/writes in its context. An app exploiting this vulnerability only needs to declare and request the single missing permission and no user interaction is required beyond installing and running a third-party app. The software build fingerprints for each confirmed vulnerable device are as follows: TCL 10L (TCL/T770B/T1LITE:11/RKQ1.210107.001/8BIC:user/release-keys) and TCL 30Z (TCL/4188R/JettaATT:12/SP1A.210812.016/LV8E:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU5P:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU61:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU66:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU68:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU6P:user/release-keys, and TCL/T602DL/JettaTF:12/SP1A.210812.016/vU6X:user/release-keys). This malicious app declares the missing permission named com.tct.smart.switchphone.permission.SWITCHDATA as a normal permission, requests the missing permission, and uses it to interact with the com.tct.smart.switchdata.DataService service component that is declared in vulnerable apps that execute with "system" privileges to perform arbitrary file reads/writes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38295?
CVE-2023-38295 has a high severity rating due to the exploitation potential associated with missing permissions in pre-installed apps.
How do I fix CVE-2023-38295?
To address CVE-2023-38295, ensure that the affected apps are updated to a version that includes the necessary permissions.
What devices are affected by CVE-2023-38295?
CVE-2023-38295 affects certain builds of the TCL 30Z and TCL 10 Android devices that come with vulnerable pre-installed apps.
What are the consequences of CVE-2023-38295 if exploited?
Exploitation of CVE-2023-38295 can lead to unauthorized access to sensitive data due to the lack of runtime protection.
Is there a workaround for CVE-2023-38295?
As a temporary workaround for CVE-2023-38295, users can uninstall the vulnerable pre-installed apps if they are not essential for device functionality.