CVE-2018-15000
Last modified
CVE-2018-15000 is a vulnerability of currently unknown severity. The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.smartshot (versionCode=1, versionName=3.0.0). This app contains an exported service named com.vivo.smartshot.ui.service.ScreenRecordService that will record the screen for 60 minutes and write the mp4 file to a location of the user's choosing. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.smartshot (versionCode=1, versionName=3.0.0). This app contains an exported service named com.vivo.smartshot.ui.service.ScreenRecordService that will record the screen for 60 minutes and write the mp4 file to a location of the user's choosing. Normally, a recording notification will be visible to the user, but we discovered an approach to make it mostly transparent to the user by quickly removing a notification and floating icon. The user can see a floating icon and notification appear and disappear quickly due to quickly stopping and restarting the service with different parameters that do not interfere with the ongoing screen recording. The screen recording lasts for 60 minutes and can be written directly to the attacking app's private directory.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vivo | V7 Firmware | All versions |
References
- https://www.kryptowire.comThird Party Advisory
- https://www.kryptowire.com/portal/android-firmware-defcon-2018/Third Party Advisory
- https://www.kryptowire.com/portal/wp-content/uploads/2018/12/DEFCON-26-Johnson-and-Stavrou-Vulnerable-Out-of-the-Box-An-Eval-of-Android-Carrier-Devices-WP-Updated.pdfTechnical Description, Third Party Advisory
- https://www.kryptowire.comThird Party Advisory
- https://www.kryptowire.com/portal/android-firmware-defcon-2018/Third Party Advisory
- https://www.kryptowire.com/portal/wp-content/uploads/2018/12/DEFCON-26-Johnson-and-Stavrou-Vulnerable-Out-of-the-Box-An-Eval-of-Android-Carrier-Devices-WP-Updated.pdfTechnical Description, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-15000?
How severe is CVE-2018-15000?
How do I fix CVE-2018-15000?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-14994The Essential Phone Android device with a build fingerprint …
- CVE-2018-14995The ZTE Blade Vantage Android device with a build fingerprin…
- CVE-2018-14996The Oppo F5 Android device with a build fingerprint of OPPO/…
- CVE-2018-14997The Leagoo P1 Android device with a build fingerprint of sp7…
- CVE-2018-14998The Leagoo P1 Android device with a build fingerprint of sp7…
- CVE-2018-14999The Leagoo P1 device with a build fingerprint of sp7731c_1h1…
- CVE-2018-15001The Vivo V7 Android device with a build fingerprint of vivo/…
- CVE-2018-15002The Vivo V7 device with a build fingerprint of vivo/1718/171…
- CVE-2018-15003The Coolpad Defiant (Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/09…
- CVE-2018-15004The Coolpad Canvas device with a build fingerprint of Coolpa…
- CVE-2018-15005The ZTE ZMAX Champ Android device with a build fingerprint o…
- CVE-2018-15006The ZTE ZMAX Champ Android device with a build fingerprint o…
Are you affected by CVE-2018-15000?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
