Learn about CVE-2019-15359 affecting the Haier A6 Android device, allowing unauthorized system property modifications by co-located apps. Find mitigation steps here.
The Haier A6 Android device is vulnerable to unauthorized modifications due to a pre-installed application, com.mediatek.wfo.impl, allowing co-located apps to access a system property interface.
Understanding CVE-2019-15359
This CVE identifies a security issue in the Haier A6 Android device that enables unauthorized changes to system properties.
What is CVE-2019-15359?
The Haier A6 Android device, specifically the version Haier/A6/A6:8.1.0/O11019/1534219877:userdebug/release-keys, contains an app named com.mediatek.wfo.impl that permits any co-located app to make unauthorized modifications to a system property.
The Impact of CVE-2019-15359
This vulnerability could lead to unauthorized access and modifications by malicious apps, potentially compromising the device's security and user data.
Technical Details of CVE-2019-15359
The technical aspects of this CVE are as follows:
Vulnerability Description
The pre-installed app com.mediatek.wfo.impl on the Haier A6 Android device allows unauthorized modifications to system properties through a publicly available interface.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability arises from the com.mediatek.wfo.impl app granting access to system properties without proper authorization, enabling co-located apps to make unauthorized changes.
Mitigation and Prevention
To address CVE-2019-15359, consider the following steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates