CVE-2023-38296: Infoleak
Various software builds for the following TCL 30Z and TCL A3X devices leak the ICCID to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in Android 10 and higher, but in these instances they are leaked by a high-privilege process and can be obtained indirectly. The software build fingerprints for each confirmed vulnerable device are as follows: TCL 30Z (TCL/4188R/JettaATT:12/SP1A.210812.016/LV8E:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU5P:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU61:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU66:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU68:user/release-keys, TCL/T602DL/JettaTF:12/SP1A.210812.016/vU6P:user/release-keys, and TCL/T602DL/JettaTF:12/SP1A.210812.016/vU6X:user/release-keys) and TCL A3X (TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAAZ:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAB3:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAB7:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABA:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABM:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABP:user/release-keys, and TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABS:user/release-keys). This malicious app reads from the "persist.sys.tctPowerIccid" system property to indirectly obtain the ICCID.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38296?
CVE-2023-38296 is classified as a high-severity vulnerability due to its potential to leak sensitive information.
How do I fix CVE-2023-38296?
To fix CVE-2023-38296, users should apply the latest software updates from TCL that address this vulnerability.
What devices are affected by CVE-2023-38296?
CVE-2023-38296 affects the TCL 30Z running Android 12 and the TCL A3X running Android 11.
What type of information does CVE-2023-38296 expose?
CVE-2023-38296 exposes the ICCID, which is a sensitive identifier for the SIM card, to any local application.
Are there any immediate risks associated with CVE-2023-38296?
Yes, local malicious applications could exploit CVE-2023-38296 to obtain the ICCID without user permission.