CVE-2024-10576 describes a critical vulnerability in Infinix mobile devices, where a pre-loaded "com.transsion.agingfunction" application exposes an unsecured broadcast receiver. This flaw allows an attacker to remotely trigger a factory reset without requiring any Android system permissions, impacting all Infinix devices. With a CVSS score of 9.4 (CRITICAL), the vulnerability is easily exploitable with low attack complexity and no user interaction, leading to complete loss of data and device availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Infinix Mobile | Com.Transsion.Agingfunction | 13CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:X/R:I/V:D/RE:X/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.3 Mastodon, and 1.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.