CVE-2023-38302: Infoleak
A certain software build for the Sharp Rouvo V device (SHARP/VZWSTTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN00530:user/release-keys) leaks the Wi-Fi MAC address and the Bluetooth MAC address to system properties that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in Android 10 and higher, but in this instance they are leaked by a high-privilege process and can be obtained indirectly. This malicious app reads from the "ro.boot.wifimac" system property to indirectly obtain the Wi-Fi MAC address and reads the "ro.boot.btmac" system property to obtain the Bluetooth MAC address.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38302?
CVE-2023-38302 is classified as a high severity vulnerability due to its ability to leak sensitive MAC address information.
How do I fix CVE-2023-38302?
To mitigate CVE-2023-38302, users should update to the latest software version that addresses this vulnerability.
What devices are affected by CVE-2023-38302?
CVE-2023-38302 specifically affects the Sharp Rouvo V device.
What data is leaked in CVE-2023-38302?
CVE-2023-38302 leaks both the Wi-Fi MAC address and the Bluetooth MAC address to system properties.
Can local apps access the data leaked by CVE-2023-38302?
Yes, any local app on the affected device can access the leaked MAC address information without requiring special permissions.